{"id":2656,"date":"2026-09-02T16:52:31","date_gmt":"2026-09-02T16:52:31","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2656"},"modified":"2026-09-02T16:52:31","modified_gmt":"2026-09-02T16:52:31","slug":"meta-ads-push-streamrat-android-trojan-that-can-gain-near-complete-device-control","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2656","title":{"rendered":"Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">The Hacker News<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 02, 2026<\/span><\/span><span class=\"p-tags\">Malvertising \/ Mobile Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhNhCfat7BT6m53utL9Z1iMKYQv6B3QwsQdxZBzkmr1WsJpDDdFGZgHjaLuHSXMBBJSyfxtyR750K33X3GzZwYkHac_3mpIITheSY4lh8LMK-ufnQ9htwhkmfv2MRKfZKtYdROU7VuO0HMmK7BQ7FlttrQiToqHq9zffChgBIOJT8yLL5vT7JY43_FDK-A\/s1700-nu-rw-lo-l85-e365\/android-trojan.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of a new Android banking trojan called <strong>StreamRat <\/strong>that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices.<\/p>\n<p>ThreatFabric said the campaign&#8217;s advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported.<\/p>\n<p>Device takeover requires the victim to grant a succession of controls after sideloading the Android Package (APK). Users should stop the installation when a streaming app requests system controls unrelated to streaming.<\/p>\n<p>\u00abThere is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem,\u00bb ThreatFabric said in its <a href=\"https:\/\/www.threatfabric.com\/blogs\/from-meta-ads-to-full-device-takeover-uncovering-streamrat\" target=\"_blank\">StreamRat analysis<\/a>.<\/p>\n<p>ThreatFabric did not attribute the campaign to a named threat actor. Once Accessibility access is enabled, operators can capture keystrokes, display credential-stealing overlays, inspect the visible interface, and control the device remotely.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The campaign begins when the social-media lure directs an Android user to a specially crafted website. The site checks the visitor&#8217;s operating system. It displays its download button to Android devices.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The visitor can then download a file named app.apk. The victim launches the APK. The dropper asks to become the device&#8217;s default Home application, which returns the victim to its interface whenever the Home button is pressed.<\/p>\n<p>Before fetching the final payload, the dropper requests permission to establish a VPN connection. Once approved, the VPN routes device traffic into a nonfunctional interface while excluding the dropper itself.<\/p>\n<p>The dropper&#8217;s main page downloads the StreamRat payload to the public Downloads directory as update_{timestamp}.apk. The dropper next asks for permission to install applications from unknown sources.<\/p>\n<p>After approval, it installs the payload through Android&#8217;s package installation mechanism. StreamRat launches. The payload requests Accessibility access. After the user grants that permission, the malware connects to its command-and-control (C2) server.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8gW3PVosURQnp7IhueCfsOnLr5kV6JItfHtHsVFvyymmrdjN5wCKTbsVlHoxPBHOQuMRO66XOjjBXgVamzHxAQtRkLXX7q1xGIlYYrkOJTtNSo04lrvfEGAqDM8rvI24WI0zayU3INToErOvfFgcJ51Ic2CBYYhnrUKz3egL2xJbXdjkq14j8hFuuBhs\/s1700-nu-rw-lo-l85-e365\/strea,.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8gW3PVosURQnp7IhueCfsOnLr5kV6JItfHtHsVFvyymmrdjN5wCKTbsVlHoxPBHOQuMRO66XOjjBXgVamzHxAQtRkLXX7q1xGIlYYrkOJTtNSo04lrvfEGAqDM8rvI24WI0zayU3INToErOvfFgcJ51Ic2CBYYhnrUKz3egL2xJbXdjkq14j8hFuuBhs\/s1700-nu-rw-lo-l85-e365\/strea,.png\" alt=\"\" border=\"0\" data-original-height=\"1941\" data-original-width=\"3450\"\/><\/a><\/div>\n<p>The VPN interface forwards no routed traffic, causing other applications to lose internet connectivity during installation. The dropper shuts down the VPN after the payload executes, allowing StreamRat to communicate with its C2 server.<\/p>\n<p>ThreatFabric assessed that the interruption may reduce online reputation and code-analysis checks. Google Play Protect retains offline detection for known potentially harmful applications, limiting the technique&#8217;s effect on the service.<\/p>\n<p>For a visible screen capture, StreamRat invokes Android&#8217;s MediaProjection application programming interface (API), which displays a consent dialog and is typically identified by a screen-sharing indicator.<\/p>\n<p>The malware can use Accessibility to interact with the consent dialog after the victim has granted that permission. A second mode uses the Accessibility takeScreenshot() method to capture the screen outside the MediaProjection indicator.<\/p>\n<p>ThreatFabric said StreamRat was also promoted through TikTok. The report&#8217;s TikTok-specific public evidence consisted of landing-page code that can identify TikTok as the referring application. It supplied no TikTok ad record or reach figure.<\/p>\n<p>The same banners were likely displayed on Facebook and Instagram, while the primary Meta placement remained undetermined.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Applicability is tied to the installation behavior and the requested permissions, as no Android version range was published.<\/p>\n<p>The company shared the following indicators of compromise (IoCs) &#8211;<\/p>\n<ul>\n<li><strong>SHA-256<\/strong> &#8211; e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c<\/li>\n<li><strong>Package<\/strong> &#8211; io.base.one887<\/li>\n<li><strong>Application<\/strong> &#8211; Str\u03b5\u03b1mTV Pro<\/li>\n<li><strong>SHA-256<\/strong> &#8211; ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3<\/li>\n<li><strong>Package<\/strong> &#8211; io.meat.hint<\/li>\n<li><strong>Application<\/strong> &#8211; Sistema de v\u00eddeo<\/li>\n<li><strong>C2 IP<\/strong> &#8211; 45.147.28[.]59<\/li>\n<li><strong>C2 IP<\/strong> &#8211; 193.32.2[.]245<\/li>\n<\/ul>\n<p>The Meta campaign began on June 11, 2026. It ended on July 3, 2026. The campaign was identified in late July 2026. The findings were published on September 2, 2026.<\/p>\n<p>The StreamRat payload came from a GitHub account that ThreatFabric linked to an earlier Mirax campaign. The dropper closely resembled the one used in that operation.<\/p>\n<p>\u00abThe droppers are hosted using GitHub releases, with different backup links and daily package updates,\u00bb Cleafy said in its <a href=\"https:\/\/www.cleafy.com\/cleafy-labs\/mirax-a-new-android-rat-turning-infected-devices-into-potential-residential-proxy-nodes\" target=\"_blank\">Mirax report<\/a>.<\/p>\n<div class=\"cf note-b\">Found this article interesting? <span class=\"\">This article is a contributed piece from one of our valued partners.<\/span> Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ\" rel=\"noopener\" target=\"_blank\">Google News<\/a>, <a href=\"https:\/\/twitter.com\/thehackersnews\" rel=\"noopener\" target=\"_blank\">Twitter<\/a> and <a href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" rel=\"noopener\" target=\"_blank\">LinkedIn<\/a> to read more exclusive content we post.<\/div>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ue804The Hacker News\ue802Sep 02, 2026Malvertising \/ Mobile Security Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2657,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[862,281,425,539,580,235,3272,908,3271,667],"class_list":["post-2656","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-ads","tag-android","tag-control","tag-device","tag-gain","tag-meta","tag-nearcomplete","tag-push","tag-streamrat","tag-trojan"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2656","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2656"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2656\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2657"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2656"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2656"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2656"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}