A Fake Streaming App Turned Android Phones Into Remote-Controlled Devices
Zimperium says StreamRat, spread by fake Spanish TV-app ads, can remotely control Android phones and steal logins.
Zimperium reported StreamRat, an Android remote-access trojan delivered through social ads for a fake streaming service that targeted Spanish-speaking users in Spain. One Meta campaign reached about 570,000 users between June 11 and July 3, 2026, though researchers published no confirmed infection count. A dropper pushes sideloading and Accessibility access, then installs a payload that can capture input, watch the screen, overlay fake logins, and let an operator control the phone. Samples used names such as StreamTV Pro, and researchers also found operator tooling.
- StreamRat spreads through fake free-TV ads aimed at Spanish speakers.
- One Meta campaign reached about 570,000 users; infections are unconfirmed.
- After Accessibility access it can view screens, capture input, and tap remotely.
- A dropper sets itself as the home screen and can request VPN access.
- Zimperium found a multi-user control panel with malware-building tools.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha256 | ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 | StrεαmTV Pro Name used by the streaming-app sample. SHA-256 ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 StreamRat-related Android app sample. Package name io.meat. |
| sha256 | e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c | s of compromise (IoCs):- Type Indicator Description SHA-256 e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c StreamRat-related Android app sample. Package name io.base. |
Full article879 words · extracted from cybersecuritynews.com · click to collapse
A free television offer led Android users to a dangerous download. Ads for a streaming service urged them to install an app that could give criminals control of their phones, rather than access to shows. The malware behind the campaign is called StreamRat.
The ads targeted Spanish-speaking users in Spain. One campaign reached about 570,000 Meta users between June 11 and July 3, 2026.
That measures ad reach, not infections. The lure echoes fake streaming apps spreading TrickMo in another Android banking malware campaign. Analysts at Zimperium noted the campaign’s use of social media ads and a staged installation process.
Zimperium said in a report shared with Cyber Security News (CSN) that StreamRat can capture passwords, watch screens and let an operator control infected devices remotely.
The danger extends beyond stolen logins. An attacker controlling a phone may reach banking apps, messages and other sensitive accounts. The offer appeared to promise entertainment, but the goal was access to personal information and financial accounts.
Researchers have not published a confirmed number of infected devices or successful attacks, so the ad campaign’s large audience should not be mistaken for a victim count.
A Fake Streaming App
The operation starts with ads promoting a free TV service on social platforms. The linked website checks whether a visitor uses Android and hides the download option for other devices.
It then shows instructions tailored to the browser or social app the visitor used to open the page. Those instructions push users to allow installation from outside the usual app store and to enable Accessibility, a feature intended to help people use their phones.
Similar permission abuse underpins Android banking trojans using overlays, which can place convincing login pages above genuine apps.
The first malicious app, a dropper, tries to become the phone’s default home screen. Pressing the Home button then takes the user back to its instructions. It downloads and installs the main trojan before relinquishing that role.
Once the victim grants Accessibility access, StreamRat can observe what appears on screen, record typed information and perform taps or swipes.
It also lists installed apps and reports which one is open. That helps an operator decide when to show a fake banking login or request more data.
The malware offers two ways to view the screen. One uses Android’s regular screen-sharing permission, while the other repeatedly captures screenshots through Accessibility without a sharing indicator. Either view can support remote actions, letting an attacker operate the phone remotely.
StreamRat can cover the display with a black screen or a false system update while an operator continues working behind it. Its fake login pages can collect details entered by the victim. Together, these tools raise the risk of unauthorized account activity.
Before the final malware is installed, the dropper can also request VPN access and create a connection that does not carry normal traffic. Other apps temporarily lose internet access, while the dropper can still download its payload.
Researchers think this may interfere with cloud-based security checks, not disable every protection. A loss of connectivity during installation is worth investigating.
The lure mixes ordinary setup instructions with requests for powerful permissions. Other Android malware sold for remote control has likewise used fake streaming offers to bring users to harmful downloads.
Researchers found a control panel with separate user roles and malware-building tools, suggesting multiple operators could use it. The campaign’s delivery method can change, but the critical turning point remains the same: a user installs an untrusted app and grants it access to the phone.
Users should avoid app downloads offered through social ads or unfamiliar websites, and question any streaming app that requests Accessibility, screen capture or VPN access.
Organizations should review phones showing unexpected permission changes, default home-screen changes or installation from outside approved sources. For context, banking malware using fake download pages presents a similar warning about deceptive app installs.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.