A newly discovered Android banking trojan dubbed StreamRat is spreading through malicious Meta and TikTok advertisements disguised as a free TV-streaming app, according to research published by ThreatFabric.
The campaign, which primarily targeted Spanish-speaking users, reached roughly 570,000 potential victims through Meta ads alone between June 11 and July 3, 2026, before researchers uncovered the operation while tracking known IPTV-themed lures.
The infection chain begins with a slick social-engineering setup. Attackers purchase Facebook and Instagram ads promoting a bogus streaming service and route interested users to a phishing site.
StreamRat Android Trojan Hits 570K Users via Fake Meta Ads
The site uses JavaScript to detect Android devices, hiding the download option from anyone else, then walks victims through a page called “r1edmi.html” that tailors installation instructions depending on whether the click came from Instagram, TikTok, Facebook, or a browser. Every visit silently triggers a Telegram notification to the operators, and the site itself is managed through a dedicated control panel.

Victims are ultimately guided to disable Android’s unknown-sources protection and grant Accessibility Service permissions, the two keys that unlock everything StreamRat does afterward.
The downloaded APK is a dropper that first tries to become the device’s default home-screen launcher, hijacking the HOME button to keep redirecting victims back into the infection flow until the payload installs.
One of the report’s most notable findings is the dropper’s use of a deliberately broken VPN connection to sever the device’s internet access during installation.
Traffic is routed through the VPN but never actually forwarded anywhere, likely to blunt cloud-based scanning, particularly Google Play Protect’s online reputation checks, while the malicious payload installs undetected.
Once the payload launches and gains Accessibility access, the fake VPN is switched off. ThreatFabric notes this technique is becoming increasingly common across Android droppers.
Once active, StreamRat connects to its command-and-control server over a WebSocket-based RPC protocol using custom headers for device ID, model, and API level. From there, it can:
- Stream the screen live via VNC (using MediaProjection) or hidden HVNC (via Accessibility screenshots), compressing frames to WebP and skipping duplicate frames using Adler-32 checksums
- Reconstruct the UI as a text-based “Accessibility Node Viewer,” dumping the full element tree for near-real-time visibility
- Deploy overlay attacks including black-screen and fake-update overlays, plus HTML-based credential-phishing injections to intercept PINs, patterns, and login data
- Block internet access, simulate taps and swipes, unlock devices using stolen PINs, and even auto-accept MediaProjection permission prompts
ThreatFabric’s analysis of the backend panel, which includes device management, injection and overlay controls, statistics, logs, and a payload builder, points to StreamRat being sold as Malware-as-a-Service, with tiered “user,” “supervisor,” and “admin” roles designed for affiliate-style operations.

The same threat actor has reportedly also distributed GodFather and Mirax malware, suggesting a well-resourced, multi-family operation rather than a one-off campaign.
“StreamRat’s engineering deduplicated screen frames, chunked data exfiltration, and a scalable MaaS panel reflects a level of operational maturity we typically associate with commercial software vendors, not underground malware crews. That’s precisely what makes it dangerous: this isn’t a hobbyist project; it’s a product built for growth.”
Any app requesting both installation-from-unknown-sources permissions and VPN access should be treated as a red flag. Users should avoid installing streaming or “IPTV” apps promoted via social media ads and rely only on official app stores.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.