Fake TV Streaming Ads Deliver StreamRat Malware for Remote Android Device Hijacking
StreamRat, a new Android banking trojan, spreads through fake TV-streaming ads on Meta and TikTok.
ThreatFabric identified StreamRat, an Android banking trojan spread by Meta and TikTok ads impersonating a free TV-streaming service in a campaign tracked as Steamtv Esp. The ads exposed an estimated 570,000 Meta users between June 11 and July 3, 2026, overwhelmingly in Spain. A phishing site delivers a dropper that seeks unknown-source installation and Accessibility access, then installs StreamRat, which uses WebSocket command-and-control for overlays, keylogging, and visible or hidden screen capture. Researchers link the delivery infrastructure to earlier GodFather and Mirax activity and say the control panel looks like malware-as-a-service.
- Steamtv Esp. ads mainly targeted Spanish-speaking Android users.
- About 570,000 Meta users were exposed from June 11 to July 3, 2026.
- The dropper reuses infrastructure previously tied to Mirax and GodFather.
- Capabilities include overlays, keylogging, hidden screen capture, and WebSocket C2.
- A role-based panel suggests malware-as-a-service distribution.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha256 | ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 | 97718e01689d77338f1cc4a230fcb6c io.base.one887 StrεαmTV Pro ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 io.meat.hint Sistema de vídeo 45.147.28[.]59 193.32.2[.]245 |
| sha256 | e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c | tors of Compromise SHA-256 Package name Application name C2 e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c io.base.one887 StrεαmTV Pro ba83cc3c9535690191018edf73ca5c6 |
Full article790 words · extracted from gbhackers.com · click to collapse
StreamRat, a newly identified Android banking trojan distributed through deceptive Meta and TikTok advertisements impersonating a free television-streaming service.
The campaign, tracked as “Steamtv Esp.,” primarily targeted Spanish-speaking Android users and exposed an estimated 570,000 Meta users between June 11 and July 3, 2026, with Spain accounting for the overwhelming majority of observed targets.
The operation shows how cybercriminals are combining paid social-media advertising, convincing streaming-themed lures, and multi-stage Android installation flows to obtain near-complete control of victims’ devices.
StreamRat supports remote screen viewing, hidden screen capture, credential-stealing overlays, keylogging, UI-tree harvesting, display blocking, and network disruption capabilities, creating a serious account-takeover risk for mobile banking users.
ThreatFabric discovered the activity in late July while tracking Meta advertisers using television-streaming themes similar to earlier malicious IPTV campaigns.
Victims who click a promoted advertisement are taken to a phishing site that first identifies whether the visitor is using Android.
Non-Android users see an error page, while Android users get a download option and tailored installation instructions.

The campaign’s landing page determines whether the victim opened the link through Instagram, TikTok, Facebook, or a standalone browser, then adjusts its social-engineering guidance accordingly.
It instructs users to permit installations from unknown sources and later grant Android Accessibility Services privileges, a permission frequently abused by banking malware to observe and manipulate device activity.
The downloaded first-stage APK is a dropper that resembles one previously used to deploy Mirax.
ThreatFabric linked the payload delivery to a GitHub repository associated with the same user account previously connected to Mirax distribution, suggesting the actor is reusing delivery infrastructure while changing final malware families.
Researchers said the actor has now used at least GodFather, Mirax, and StreamRat.
Before installing StreamRat, the dropper attempts to establish a deliberately non-functional VPN connection.
It routes device traffic through the VPN while excluding itself, effectively depriving other apps of internet access until the final payload is installed and started.
This technique may hinder cloud-based reputation checks and online malware analysis performed by security products.
ThreatFabric said in a report shared with GBhackers, StreamRat, a new Android banking trojan promoted to Spanish-speaking users through Meta and TikTok advertisements impersonating a free TV-streaming service.
StreamRat Malware
ThreatFabric assessed that the method is more likely intended to reduce the effectiveness of online detection mechanisms than to fully bypass Google Play Protect, which can still perform offline detection of known harmful apps.
The dropper also pressures victims to set it as the device’s default Home application. That tactic ensures presses of the Home button return the user to the malicious interface, reducing the likelihood that victims interrupt the installation sequence.
Once StreamRat gains Accessibility access, the dropper removes itself as the default launcher and turns off its blocking VPN connection.
Once active, StreamRat connects to a hardcoded command-and-control server over WebSocket and immediately inventories installed applications.
It continuously tracks foreground applications, captures user-entered data, and queries its operators for maintenance or injection overlays based on the app currently visible to the victim.

The malware offers both VNC-style and hidden VNC capabilities. In conventional VNC mode, it abuses Android’s MediaProjection API to request screen-sharing permission and capture display content.
In hidden VNC mode, it uses Accessibility-based screenshot functions every 200 milliseconds, avoiding the user-visible indicators often associated with MediaProjection screen sharing.
StreamRat compresses screens into WebP images scaled to 35% of their original dimensions, conserving bandwidth while preserving enough visual detail for remote fraud operations.
It also avoids sending duplicate frames by calculating Adler-32 checksums, an optimization that limits unnecessary command-and-control traffic.
The malware’s backend panel includes pages for infected-device management, statistics, overlays, logs, payload building, dropper building, and user management.
The presence of user, supervisor, and administrator roles indicates StreamRat may be positioned as a Malware-as-a-Service offering for multiple operators.
Users should avoid APKs promoted through social-media ads, particularly offers for free premium streaming services, and should never enable unknown-source installation or Accessibility permissions for untrusted apps.
The campaign also reinforces that paid advertising can function as an initial-access channel, making ad-platform monitoring essential for fraud and mobile-threat detection teams.
Indicators of Compromise
| SHA-256 | Package name | Application name | C2 |
| e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c | io.base.one887 | StrεαmTV Pro | |
| ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 | io.meat.hint | Sistema de vídeo | 45.147.28[.]59 193.32.2[.]245 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.