StreamRat Android Banking Trojan Spread via Meta and TikTok Malvertising, Reaching an Estimated 570,950 EU Accounts
ThreatFabric and Malwarebytes report that fake free TV-streaming ads on Meta and TikTok delivered StreamRat, an Android banking trojan and infostealer that reached an estimated 570,950 EU Meta accounts (Malwarebytes: ~570,000 users), with most victims in…
ThreatFabric and Malwarebytes independently reported a malvertising campaign on Meta and TikTok promoting a fake free TV-streaming service that delivered StreamRat, a technically sophisticated Android banking trojan and infostealer targeting Spanish-speaking users. ThreatFabric's figures put the Meta ad reach at an estimated 570,950 EU accounts between June 11 and July 3, 2026, while Malwarebytes described the same campaign as reaching approximately 570,000 Meta users, with most observed victims in Spain; the figures are consistent, with the more precise figure used here, and confirmed infections were not reported. Victims were coached through sideloading APKs, with the download site tailoring instructions by device type and referral source, including enabling installs from unknown sources. Once installed, StreamRat abuses Android Accessibility to log keystrokes, capture screens and typed credentials, display fake login, black-screen and fake Android update overlays, and give attackers near-complete remote control of the device. The dropper requests default Home app and VPN permissions and routes traffic to a dead interface during installation. The payload was hosted on a GitHub account also linked to the earlier Mirax campaign. Known C2 infrastructure includes IPs 45.147.28.59 and 193.32.2.245, and no named threat actor was attributed in either report.
- Campaign ran June 11 to July 3, 2026 on Meta and was also promoted through TikTok (ThreatFabric; Malwarebytes).
- Reach figures differ slightly by source: ThreatFabric estimated 570,950 EU Meta accounts; Malwarebytes reported approximately 570,000 Meta users; confirmed infections were unreported.
- Targets Spanish-speaking users, with most observed victims located in Spain (Malwarebytes).
- StreamRat is an Android banking trojan and infostealer delivered via sideloaded APKs; the download site detected the Android device and referral source and coached users through enabling installs from unknown sources.
- Abuses Android Accessibility for keystroke logging, credential capture, credential-stealing overlays and fake login screens, screen capture, and remote device control, including black-screen and fake Android update overlays.
- Dropper requests default Home app and VPN permissions and routes traffic to a dead interface during installation (ThreatFabric).
- Payload was hosted via GitHub releases on an account linked to the earlier Mirax campaign (ThreatFabric).
- IoCs include C2 IPs 45.147.28.59 and 193.32.2.245; no named threat actor was attributed in either report.
Coverage timelineoldest first · each row is one article
- · 14d agoMeta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
The Hacker News· 55
ThreatFabric details StreamRat, a new Android banking trojan spread via Meta malvertising in Spain that reached about 571,000 EU accounts.