Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Unveiling the StreamRat Android Trojan: A Sophisticated Malware Campaign with Near-Complete Device Control




A new Android banking trojan called StreamRat has been discovered, which was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta. The malware campaign, which began on June 11, 2026, and ended on July 3, 2026, is notable for its technical sophistication and ability to gain near-complete control over infected devices. The StreamRat trojan is closely related to a previous malware campaign called Mirax, which was also promoted through GitHub releases. Threat actors targeting Spanish-speaking users in the European Union are using this malware to steal sensitive information, such as login credentials and banking data. Android users should exercise caution when downloading and installing apps from unknown sources and ensure that their devices are up to date with the latest security patches.

  • The StreamRat Android banking trojan was discovered, promoting Spanish-speaking users to download a fake TV streaming app on Meta.
  • The malware gained near-complete control over infected devices, allowing cybercriminals to capture keystrokes, display credential-stealing overlays, and control devices remotely.
  • The StreamRat trojan targeted 570,950 Meta accounts in the European Union through a fake TV streaming campaign.
  • The malware is similar to a previous campaign called Mirax, suggesting a possible connection between the two.
  • Users are advised to exercise caution when downloading and installing apps from unknown sources, and to ensure their devices are up-to-date with security patches.



  • In a recent discovery, cybersecurity researchers have shed light on a highly sophisticated Android banking trojan called StreamRat, which was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta. The malware campaign, which began on June 11, 2026, and ended on July 3, 2026, is notable for its technical sophistication and ability to gain near-complete control over infected devices.

    The StreamRat trojan was designed to sideload Android Packages (APK) onto devices, allowing operators to capture keystrokes, display credential-stealing overlays, inspect the visible interface, and control the device remotely. Once accessibility access is enabled, the malware can capture keystrokes, display credential-stealing overlays, inspect the visible interface, and control the device remotely.

    The StreamRat trojan was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta, which targeted an estimated 570,950 Meta accounts in the European Union. The campaign was designed to mimic a legitimate streaming service, with banners and ads that appeared to be from a popular TV show. However, the ads were actually links to malicious websites that would prompt users to download the StreamRat APK.

    The StreamRat trojan is closely related to a previous malware campaign called Mirax, which was also promoted through GitHub releases. The dropper used in both campaigns is similar, with different backup links and daily package updates. This suggests that the StreamRat trojan may have been developed by the same threat actor as the Mirax campaign.

    ThreatFabric, a cybersecurity research firm, has published a detailed analysis of the StreamRat trojan, which includes indicators of compromise (IoCs), such as SHA-256 hashes, package names, and C2 IP addresses. The analysis reveals that the StreamRat trojan was designed to capture sensitive information, such as login credentials and banking data, and to provide operators with near-complete control over infected devices.

    The StreamRat trojan uses a combination of techniques to achieve its goals, including the use of accessibility access to capture keystrokes and display credential-stealing overlays. It also uses the MediaProjection API to display a consent dialog and capture the screen outside of the MediaProjection indicator. This allows the malware to obtain sensitive information, such as login credentials and banking data, without the user's knowledge or consent.

    The StreamRat trojan is a significant threat to Android users, particularly in the European Union, where it targeted an estimated 570,950 Meta accounts. The malware's ability to gain near-complete control over infected devices makes it a highly sophisticated and powerful tool for cybercriminals.

    In light of this discovery, it is essential for Android users to be aware of the risks associated with fake television-streaming campaigns and to exercise caution when downloading and installing apps from unknown sources. Users should also ensure that their devices are up to date with the latest security patches and that they have a reputable antivirus software installed to detect and prevent malware infections.

    In conclusion, the StreamRat Android trojan is a highly sophisticated malware campaign that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta. The malware's ability to gain near-complete control over infected devices makes it a significant threat to Android users, particularly in the European Union. It is essential for users to be aware of the risks associated with fake television-streaming campaigns and to exercise caution when downloading and installing apps from unknown sources.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Unveiling-the-StreamRat-Android-Trojan-A-Sophisticated-Malware-Campaign-with-Near-Complete-Device-Control-ehn.shtml

  • https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html


  • Published: Wed Sep 2 12:02:15 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us