StreamRat Android malware spreads through Meta and TikTok ads
Malwarebytes reports StreamRat Android banking trojan spread via Meta and TikTok ads reaching roughly 570,000 users, mostly in Spain.
Malwarebytes researchers uncovered a malicious advertising campaign on Meta and TikTok promoting a fake free TV-streaming service that delivered the StreamRat Android banking trojan and infostealer. The ads, aimed at Spanish-speaking users with most victims in Spain, reached approximately 570,000 Meta users in a campaign running June 11 through July 3, 2026. The download site detected Android devices and the referral source, then coached users through sideloading steps including enabling installs from unknown sources. StreamRat can monitor the screen, capture typed credentials, display fake login screens, and give attackers remote control, including black-screen and fake Android update overlays.
- StreamRat is an Android banking trojan and infostealer distributed through paid Meta and TikTok ads.
- Ads reached roughly 570,000 Meta users; campaign ran June 11 to July 3, 2026.
- Targets Spanish-speaking users, with most observed victims located in Spain.
- Malware monitors screens, captures input, shows fake login/update screens, and enables remote device control.
- Distribution site tailored instructions by device type and referral source to coach users through sideloading.
Full article690 words · extracted from malwarebytes.com · click to collapse
A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users.
The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok.
The available data shows the ads’ reach, not the number of downloads or infections, but it demonstrates how quickly paid advertising can put a scam in front of a very large audience.
The ads promoted an Android banking Trojan and infostealer called StreamRat. It can monitor what’s on screen, capture information typed into apps, show convincing fake screens to steal usernames and passwords, and allow attackers to control the device remotely.
We often warn people not to click suspicious links in unexpected texts or emails. But malicious advertising is harder to recognize because it appears in the same feeds where people expect to find promotions, videos, and recommendations.
This campaign is a perfect demonstration of why “after-the-fact” ad checks are inadequate when it comes to protecting social media users. Attackers used familiar social media advertising and carefully tailored instructions to turn casual interest in free entertainment into a risky app installation.
How the attack worked
The ad led victims to a website posing as a streaming platform. The site checked whether a visitor was using Android. Non-Android visitors were simply prevented from downloading anything, while Android users were shown an app download option. This is a common way for scammers to concentrate their efforts on devices their malware can infect.
The site also identified whether someone had arrived through Instagram, TikTok, Facebook, or a regular browser. It then displayed instructions suited to that situation, including steps to allow the browser to install apps from “unknown sources.” In other words, this was not a generic malicious download page: It was designed to coach people through the security warnings that would normally make them stop and think.
StreamRat is an Android banking Trojan and infostealer. It can monitor what’s on screen, capture information typed into apps, show convincing fake screens to collect usernames and passwords, and enable attackers to operate the device remotely. The researchers also found options to cover the screen with a black page or fake Android update screen. These can distract victims while criminals interact with the phone behind the scenes.
How to stay safe
While this campaign targeted Spanish-speaking people, primarily in Spain, the following guidelines can help anyone avoid similar attacks.
- Avoid installing Android apps from ads, direct-download websites, social media messages, sponsored search results, or links sent by strangers.
- Download apps through Google Play whenever possible, and check the developer’s name, reviews, and app history rather than relying on an ad.
- Before enabling installation from “unknown sources,” read our guide, Sideloading on Android: What it is, why it’s risky, and how to do it more safely.
- Be very cautious when an app asks for Accessibility access, screen-sharing permission, Device Admin privileges, or permission to become the default launcher. Permissions that don’t line up with the intended use of the app are very suspicious.
- Use an up-to-date, real-time anti-malware solution on all your devices.
What to do if you installed a suspicious app
If you installed a suspicious APK and granted it Accessibility access, disconnect the phone from Wi-Fi and mobile data. If possible, revoke the app’s Accessibility access and remove it. Use another device to change relevant passwords and contact your bank if you used banking apps on the infected phone. A factory reset may be necessary if you cannot confidently remove the infection.
Malwarebytes for Android detects the components of StreamRat as Android/Trojan.Agent.ACRAEEF8A36H36, Android/Trojan.Agent.ACR02DB0614H7, and Android/Trojan.Dropper.ACR9B7ECE83D1.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
About the author
Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.malwarebytes.com/blog/news/2026/09/streamrat-android-malware-spreads-through-meta-and-tiktok-ads