Advisory
Published 2026-09-02
Verified 2026-09-19

StreamRat Android banking trojan pushed via Meta ads to Spanish-speaking users

ThreatFabric (2 September 2026) details StreamRat, an Android banking trojan promoted through a fake television-streaming campaign on Meta aimed at Spanish-speaking users. ThreatFabric estimates about 570,950 Meta accounts in the EU saw the ad at least once; infected-device totals are not published. After sideloading app.apk, the dropper seeks default Home-app status, a VPN permission that blackholes other apps' traffic during install, unknown-sources install rights, then Accessibility access for the StreamRat payload (keylogging, credential overlays, UI inspection, remote control) before talking to C2. ThreatFabric does not name an attributed actor. Users should refuse streaming APKs that request Home, VPN, or Accessibility controls unrelated to playback; enterprises with BYOD Android in AU/EU travel cohorts should watch for sideloaded streaming lures.

Product
Android (StreamRat banking trojan via Meta ads)
Exploited in Australia?
unknown
Patch to
Do not sideload streaming APKs from ads; revoke Accessibility/Home/VPN for unknown apps; keep Play Protect on

Primary: ThreatFabric StreamRat analysis (2 Sep 2026) · Vendor: ThreatFabric (vendor research) · The Hacker News (2 Sep 2026)

tech identity