Cybersecurity researchers have identified a new Android banking trojan, StreamRat, which is being promoted through deceptive television-streaming campaigns on Meta platforms. The malware is designed to target Spanish-speaking users, with advertisements reaching an estimated 570,950 Meta accounts in the European Union.
The attack begins with social media ads directing Android users to a malicious website. This site prompts users to download an APK file named 'app.apk'. Upon installation, the dropper requests to become the default Home application and then seeks permission to establish a VPN connection. This VPN routes device traffic through a nonfunctional interface, causing other apps to lose internet connectivity while the dropper operates.
The dropper then downloads the StreamRat payload as 'update_{timestamp}.apk' and requests permission to install applications from unknown sources. After approval, the payload is installed, and StreamRat launches, requesting Accessibility access. Once granted, the malware connects to its command-and-control (C2) server, and the VPN is shut down.
Once StreamRat obtains Accessibility access, its operators can perform various malicious activities. These include capturing keystrokes, displaying credential-stealing overlays, inspecting the device's visible interface, and gaining remote control over the device. ThreatFabric, the cybersecurity firm that analyzed StreamRat, noted its technical sophistication, suggesting experienced developers are behind it.
Users are advised to be cautious when sideloading applications. If a streaming application requests system controls unrelated to its core function, such as becoming the default Home app or establishing a VPN, the installation should be stopped immediately. The total number of infected devices and confirmed victims of this campaign remains undisclosed.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new Android banking trojan named StreamRat is being distributed through fake TV streaming ads on Meta, primarily targeting Spanish-speaking users. This sophisticated malware can gain extensive control over infected devices, including keystroke logging and remote control, after users grant a series of permissions.