ZeroHour
Story · 1 source · 1 articlefirst updated ()

StreamRat Android Banking Trojan Spread via Meta and TikTok Malvertising, Reaching an Estimated 570,950 EU Accounts

mediumMalwareexploited in the wildimportance 55
What's new: Initial merged summary (no prior story). Combines The Hacker News/ThreatFabric (2026-09-02) and Malwarebytes Labs (2026-09-03) reporting; reconciles the reach figures (570,950 EU accounts per ThreatFabric vs approximately 570,000 users per Malwarebytes) and adds Malwarebytes details on the Spain concentration, device- and referral-aware sideloading instructions, and black-screen/fake update…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

ThreatFabric and Malwarebytes report that fake free TV-streaming ads on Meta and TikTok delivered StreamRat, an Android banking trojan and infostealer that reached an estimated 570,950 EU Meta accounts (Malwarebytes: ~570,000 users), with most victims in…

ThreatFabric and Malwarebytes independently reported a malvertising campaign on Meta and TikTok promoting a fake free TV-streaming service that delivered StreamRat, a technically sophisticated Android banking trojan and infostealer targeting Spanish-speaking users. ThreatFabric's figures put the Meta ad reach at an estimated 570,950 EU accounts between June 11 and July 3, 2026, while Malwarebytes described the same campaign as reaching approximately 570,000 Meta users, with most observed victims in Spain; the figures are consistent, with the more precise figure used here, and confirmed infections were not reported. Victims were coached through sideloading APKs, with the download site tailoring instructions by device type and referral source, including enabling installs from unknown sources. Once installed, StreamRat abuses Android Accessibility to log keystrokes, capture screens and typed credentials, display fake login, black-screen and fake Android update overlays, and give attackers near-complete remote control of the device. The dropper requests default Home app and VPN permissions and routes traffic to a dead interface during installation. The payload was hosted on a GitHub account also linked to the earlier Mirax campaign. Known C2 infrastructure includes IPs 45.147.28.59 and 193.32.2.245, and no named threat actor was attributed in either report.

  • Campaign ran June 11 to July 3, 2026 on Meta and was also promoted through TikTok (ThreatFabric; Malwarebytes).
  • Reach figures differ slightly by source: ThreatFabric estimated 570,950 EU Meta accounts; Malwarebytes reported approximately 570,000 Meta users; confirmed infections were unreported.
  • Targets Spanish-speaking users, with most observed victims located in Spain (Malwarebytes).
  • StreamRat is an Android banking trojan and infostealer delivered via sideloaded APKs; the download site detected the Android device and referral source and coached users through enabling installs from unknown sources.
  • Abuses Android Accessibility for keystroke logging, credential capture, credential-stealing overlays and fake login screens, screen capture, and remote device control, including black-screen and fake Android update overlays.
  • Dropper requests default Home app and VPN permissions and routes traffic to a dead interface during installation (ThreatFabric).
  • Payload was hosted via GitHub releases on an account linked to the earlier Mirax campaign (ThreatFabric).
  • IoCs include C2 IPs 45.147.28.59 and 193.32.2.245; no named threat actor was attributed in either report.

Coverage timeline

  1. · 14d ago
    The Hacker News· 55
    Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

    ThreatFabric details StreamRat, a new Android banking trojan spread via Meta malvertising in Spain that reached about 571,000 EU accounts.