StreamRat Android banking trojan with remote-control capabilities
Malware Activity
Summary
Hide ▲
Show ▼
StreamRat is an Android banking trojan promoted through a fake television-streaming campaign on Meta that targeted Spanish-speaking users in Spain and reached an estimated 570,950 Meta accounts in the European Union. The lure used a crafted website and a sideloaded APK, then pushed intrusive permissions so the malware could gain Accessibility access and connect to command-and-control infrastructure. Once installed, StreamRat could capture keystrokes, show credential-stealing overlays, take screenshots, and remotely control infected devices. The same reporting also links StreamRat to TikTok-driven counterfeit streaming lures and to activity that abused Android accessibility and the MediaProjection API to harvest sensitive data.
Related Happenings
Mantax Otax Android malware activity
Malware Activity
H score32
First: 11.09.2026 00:40
Last: 11.09.2026 00:40
Sources 1
About this happening:
The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
Mantax Otax Android malware activity
Malware ActivityAbout this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....
StreamRat Meta ad campaign targeting Spanish-speaking users
Campaign
H score48
First: 02.09.2026 15:22
Last: 02.09.2026 15:22
Sources 1
How related:
ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported.
About this happening:
A Meta ad campaign is pushing StreamRat to Spanish-speaking users, expanding exposure to an Android banking trojan that can steal credentials and take over devices. Th...
StreamRat Meta ad campaign targeting Spanish-speaking users
CampaignHow related: ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported.
About this happening: A Meta ad campaign is pushing StreamRat to Spanish-speaking users, expanding exposure to an Android banking trojan that can steal credentials and take over devices. Th...
Manic Android malware activity with offline relay exfiltration
Malware Activity
H score29
First: 20.08.2026 13:02
Last: 20.08.2026 13:02
Sources 1
About this happening:
Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
Manic Android malware activity with offline relay exfiltration
Malware ActivityAbout this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware Activity
H score20
First: 12.08.2026 17:30
Last: 12.08.2026 17:30
Sources 1
About this happening:
WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware ActivityAbout this happening: WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
Timeline
-
02.09.2026 15:22 1 articles · 14d ago
Meta campaign begins pushing StreamRat through fake streaming ads
Campaign Scope UpdateOn June 11, 2026, a fake television-streaming campaign on Meta begins targeting Spain with StreamRat, an Android banking trojan delivered through a lure that directs Android users to a crafted website and a sideloaded APK.
Show sources
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control — thehackernews.com — 02.09.2026 15:22
-
02.09.2026 15:22 1 articles · 14d ago
Meta campaign ends after promoting StreamRat in Spain
Campaign Scope UpdateOn July 3, 2026, the Meta campaign ends after running against Spanish-speaking users in Spain and reaching an estimated 570,950 Meta accounts in the European Union that saw the ad at least once.
Show sources
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control — thehackernews.com — 02.09.2026 15:22
-
02.09.2026 15:22 3 articles · 14d ago
ThreatFabric publishes StreamRat Android banking trojan analysis
Initial DisclosureThreatFabric discloses StreamRat, a new Android banking trojan that was promoted through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. The analysis says the campaign focused on Spain, reached an estimated 570,950 Meta accounts in the EU, was identified in late July 2026, and was not attributed to a named threat actor.
Show sources
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control — thehackernews.com — 02.09.2026 15:22
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control — thehackernews.com — 02.09.2026 15:22
- Google Play Early Access Abused to Push Thousands of Deceptive Android Apps — thehackernews.com — 10.09.2026 17:36