Find notable cyber news and cases, enriched with sources, timelines, and signals.

StreamRat Android banking trojan with remote-control capabilities

Malware Activity
First reported
Last updated
Happening score
H score 42
1 unique sources, 2 articles

Summary

Hide ▲

StreamRat is an Android banking trojan promoted through a fake television-streaming campaign on Meta that targeted Spanish-speaking users in Spain and reached an estimated 570,950 Meta accounts in the European Union. The lure used a crafted website and a sideloaded APK, then pushed intrusive permissions so the malware could gain Accessibility access and connect to command-and-control infrastructure. Once installed, StreamRat could capture keystrokes, show credential-stealing overlays, take screenshots, and remotely control infected devices. The same reporting also links StreamRat to TikTok-driven counterfeit streaming lures and to activity that abused Android accessibility and the MediaProjection API to harvest sensitive data.

Related Happenings

Mantax Otax Android malware activity

Malware Activity
H score32 First: 11.09.2026 00:40 Last: 11.09.2026 00:40 Sources 1

About this happening: The Mantax Otax Android malware now combines ransomware and spyware features, putting older Android devices at risk of file encryption, data theft, and harassment....

StreamRat Meta ad campaign targeting Spanish-speaking users

Campaign
H score48 First: 02.09.2026 15:22 Last: 02.09.2026 15:22 Sources 1

How related: ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported.

About this happening: A Meta ad campaign is pushing StreamRat to Spanish-speaking users, expanding exposure to an Android banking trojan that can steal credentials and take over devices. Th...

Manic Android malware activity with offline relay exfiltration

Malware Activity
H score29 First: 20.08.2026 13:02 Last: 20.08.2026 13:02 Sources 1

About this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...

ToxicPanda 2.0 Android banking trojan expansion

Malware Activity
H score28 First: 20.08.2026 13:00 Last: 20.08.2026 13:00 Sources 1

About this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...

WindRelay NFC relay malware deployed with SpyNote RAT

Malware Activity
H score20 First: 12.08.2026 17:30 Last: 12.08.2026 17:30 Sources 1

About this happening: WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...

Timeline

  1. 02.09.2026 15:22 1 articles · 14d ago

    Meta campaign begins pushing StreamRat through fake streaming ads

    Campaign Scope Update

    On June 11, 2026, a fake television-streaming campaign on Meta begins targeting Spain with StreamRat, an Android banking trojan delivered through a lure that directs Android users to a crafted website and a sideloaded APK.

    Show sources
  2. 02.09.2026 15:22 3 articles · 14d ago

    ThreatFabric publishes StreamRat Android banking trojan analysis

    Initial Disclosure

    ThreatFabric discloses StreamRat, a new Android banking trojan that was promoted through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. The analysis says the campaign focused on Spain, reached an estimated 570,950 Meta accounts in the EU, was identified in late July 2026, and was not attributed to a named threat actor.

    Show sources