StreamRat Android Trojan Spread via Fake TV-Streaming Ads on Meta and TikTok
A new Android trojan called StreamRat, pushed by ads for a fake free TV-streaming service aimed at Spanish-speaking users, exposed roughly 570,000 Meta users and can remotely control infected phones.
Two research teams, ThreatFabric (reported by GBHackers) and Zimperium (reported by Cyber Security News), independently describe StreamRat, an Android trojan delivered through social media ads on Meta and TikTok impersonating a free TV-streaming service. ThreatFabric tracks the campaign as Steamtv Esp. One Meta campaign exposed an estimated 570,000 users between June 11 and July 3, 2026, overwhelmingly Spanish speakers in Spain; no confirmed infection count has been published. A phishing site delivers a dropper that requests unknown-source (sideloaded) installation and Android Accessibility access; Zimperium adds that the dropper can set itself as the home screen and request VPN access. The installed payload uses WebSocket command-and-control to perform overlay attacks, keylogging, visible and hidden screen capture, and full remote device control by an operator. Samples used names such as StreamTV Pro. ThreatFabric links the delivery infrastructure to earlier GodFather and Mirax activity, and both teams describe a multi-user, role-based operator panel with malware-building tools, consistent with malware-as-a-service. The sources differ on framing: GBHackers/ThreatFabric call StreamRat a banking trojan, while Zimperium characterizes it as a remote-access trojan; the reported facts otherwise align.
- Malware name: StreamRat; campaign tracked as Steamtv Esp. (ThreatFabric).
- Delivery: ads on Meta and TikTok for a fake free TV-streaming service, aimed at Spanish-speaking Android users in Spain.
- Scale: one Meta campaign exposed an estimated 570,000 users between June 11 and July 3, 2026; no confirmed infection count published.
- Infection chain: phishing site delivers a dropper requesting unknown-source installation and Accessibility access; the dropper can also set itself as the home screen and request VPN access (Zimperium).
- Capabilities: WebSocket command-and-control, overlay attacks, keylogging/input capture, visible and hidden screen capture, and remote device control.
- Sample names include StreamTV Pro (Zimperium).
- Infrastructure overlap: delivery infrastructure previously tied to GodFather and Mirax activity (ThreatFabric).
- A multi-user, role-based control panel with malware-building tools suggests malware-as-a-service distribution.
Coverage timelineoldest first · each row is one article
- · 4d agoFake TV Streaming Ads Deliver StreamRat Malware for Remote Android Device Hijacking
GBHackers· 76
StreamRat, a new Android banking trojan, spreads through fake TV-streaming ads on Meta and TikTok.
- · 3d agoA Fake Streaming App Turned Android Phones Into Remote-Controlled Devices
Cyber Security News· 62
Zimperium says StreamRat, spread by fake Spanish TV-app ads, can remotely control Android phones and steal logins.