Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

The Hacker News by The Hacker News
September 2, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


The Hacker NewsSep 02, 2026Malvertising / Mobile Security

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices.

ThreatFabric said the campaign’s advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported.

Device takeover requires the victim to grant a succession of controls after sideloading the Android Package (APK). Users should stop the installation when a streaming app requests system controls unrelated to streaming.

“There is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem,” ThreatFabric said in its StreamRat analysis.

ThreatFabric did not attribute the campaign to a named threat actor. Once Accessibility access is enabled, operators can capture keystrokes, display credential-stealing overlays, inspect the visible interface, and control the device remotely.

The campaign begins when the social-media lure directs an Android user to a specially crafted website. The site checks the visitor’s operating system. It displays its download button to Android devices.

The visitor can then download a file named app.apk. The victim launches the APK. The dropper asks to become the device’s default Home application, which returns the victim to its interface whenever the Home button is pressed.

Before fetching the final payload, the dropper requests permission to establish a VPN connection. Once approved, the VPN routes device traffic into a nonfunctional interface while excluding the dropper itself.

The dropper’s main page downloads the StreamRat payload to the public Downloads directory as update_{timestamp}.apk. The dropper next asks for permission to install applications from unknown sources.

After approval, it installs the payload through Android’s package installation mechanism. StreamRat launches. The payload requests Accessibility access. After the user grants that permission, the malware connects to its command-and-control (C2) server.

The VPN interface forwards no routed traffic, causing other applications to lose internet connectivity during installation. The dropper shuts down the VPN after the payload executes, allowing StreamRat to communicate with its C2 server.

ThreatFabric assessed that the interruption may reduce online reputation and code-analysis checks. Google Play Protect retains offline detection for known potentially harmful applications, limiting the technique’s effect on the service.

For a visible screen capture, StreamRat invokes Android’s MediaProjection application programming interface (API), which displays a consent dialog and is typically identified by a screen-sharing indicator.

The malware can use Accessibility to interact with the consent dialog after the victim has granted that permission. A second mode uses the Accessibility takeScreenshot() method to capture the screen outside the MediaProjection indicator.

ThreatFabric said StreamRat was also promoted through TikTok. The report’s TikTok-specific public evidence consisted of landing-page code that can identify TikTok as the referring application. It supplied no TikTok ad record or reach figure.

The same banners were likely displayed on Facebook and Instagram, while the primary Meta placement remained undetermined.

Applicability is tied to the installation behavior and the requested permissions, as no Android version range was published.

The company shared the following indicators of compromise (IoCs) –

  • SHA-256 – e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c
  • Package – io.base.one887
  • Application – StrεαmTV Pro
  • SHA-256 – ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3
  • Package – io.meat.hint
  • Application – Sistema de vídeo
  • C2 IP – 45.147.28[.]59
  • C2 IP – 193.32.2[.]245

The Meta campaign began on June 11, 2026. It ended on July 3, 2026. The campaign was identified in late July 2026. The findings were published on September 2, 2026.

The StreamRat payload came from a GitHub account that ThreatFabric linked to an earlier Mirax campaign. The dropper closely resembled the one used in that operation.

“The droppers are hosted using GitHub releases, with different backup links and daily package updates,” Cleafy said in its Mirax report.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.





Source link

The Hacker News

The Hacker News

Next Post

Real Time Automation's John Rinaldi Accepted into Forbes Technology Council; Champions Scalable, Open Smart Manufacturing

Recommended.

VIP Play, Inc. Approved to Renew Tennessee Sports Gaming Operator License, Following Launch of New VIP Play Mobile Betting App in Tennessee

VIP Play, Inc. Approved to Renew Tennessee Sports Gaming Operator License, Following Launch of New VIP Play Mobile Betting App in Tennessee

May 15, 2025
AWS Vs. Microsoft Vs. Google Cloud Earnings Q4 2025 Face-Off

AWS Vs. Microsoft Vs. Google Cloud Earnings Q4 2025 Face-Off

February 9, 2026

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio