news.mlab.sh
Back to the feed
threat-intel

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

High
Summary

A new Android banking trojan, StreamRat, has been promoted through a deceptive Meta advertising campaign targeting Spanish-speaking users. The campaign leveraged fake television-streaming ads to trick users into sideloading the malware, which then gained near-complete control of their devices by requesting Accessibility permissions and establishing a VPN connection. ThreatFabric linked the campaign to a previous Mirax operation and identified the malware as a sophisticated threat developed by experienced Android malware developers.

A new Android banking trojan called StreamRat has been promoted through a deceptive Meta advertising campaign targeting Spanish-speaking users. The campaign began on June 11, 2026 and ended on July 3, 2026, with the findings published on September 2, 2026. The campaign utilized fake television-streaming ads on Meta platforms (Facebook, Instagram, and potentially TikTok) to lure users to a specially crafted website.

When a user visited the site, it checked their operating system and, if it was an Android device, offered to download an APK file named ‘app.apk’. After downloading, the user launched the APK, which then requested permission to become the device’s default Home application, returning the user to its interface whenever the Home button was pressed. Before delivering the final payload, the dropper requested permission to establish a VPN connection, which, once approved, would route device traffic through a nonfunctional interface, excluding the dropper itself.

ThreatFabric linked the campaign to a previous Mirax operation, noting that the droppers were hosted using GitHub releases with different backup links and daily package updates. The malware uses Accessibility to interact with the consent dialog after the user has granted that permission, and a second mode uses the Accessibility takeScreenshot() method to capture the screen outside the MediaProjection indicator.

ThreatFabric provided the following Indicators of Compromise (IoCs):

  • SHA-256 - e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c
  • Package - io.base.one887
  • Application - StrεαmTV Pro
  • SHA-256 - ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3
  • Package - io.meat.hint
  • Application - Sistema de vídeo
  • C2 IP - 45.147.28[.]59
  • C2 IP - 193.32.2[.]245

The campaign was identified in late July 2026, and the malware payload originated from a GitHub account linked to the Mirax campaign. The dropper closely resembled the one used in that operation. ThreatFabric assessed that the interruption may reduce online reputation and code-analysis checks.

Read the full article at The Hacker News