The record
Written from the 1 report below. Nothing here is unsourced.
- A new Android banking trojan called StreamRat was distributed through fake TV-streaming ads on Meta, targeting Spanish-speaking users.
- ThreatFabric estimates the ad reached about 570,950 Meta accounts in the European Union between June 11 and July 3, 2026.
- The trojan can gain near-complete control of a device once the victim grants a series of permissions, including Accessibility access, after sideloading an APK file.
- With that access, attackers can capture keystrokes, steal credentials through fake overlays, take screenshots, and control the phone remotely.
- Users should stop installing any streaming app that requests system controls unrelated to streaming, since the malware spreads only through sideloaded downloads from crafted websites.
What to watch next
- ThreatFabric did not attribute the campaign to any named actor, so future attribution findings are worth tracking.
- Reach on TikTok and confirmed victim counts remain unreported, so updated figures may emerge.
- The payload links to an earlier Mirax campaign via GitHub-hosted droppers, so new campaigns reusing that infrastructure are possible.
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
ThreatFabric
1 quote · 1 outlet
“There is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem”
In the article
…takeover requires the victim to grant a succession of controls after sideloading the Android Package (APK). Users should stop the installation when a streaming app requests system controls unrelated to streaming. " There is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem ," ThreatFabric said in its StreamRat analysis. ThreatFabric did not attribute the campaign to a named threat actor. Once Accessibility access is enabled, operators can capture keystrokes, display credential-stealing…
Coverage1
All filed from India
Named Spain · European Union · Android · GitHub · Google · Meta · TikTok · StreamRat · ThreatFabric
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
