Threat Intelligence

Fake TV-Streaming Ads on Meta Spread StreamRat Android Trojan

The Hacker News · 2 Sept 2026
Key Takeaway Only install apps from official app stores, be wary of ads pushing streaming or free content apps, and ensure staff mobile devices used for banking have security software and Play Protect enabled.

Security researchers at ThreatFabric have uncovered a malicious advertising campaign on Meta platforms that promotes a fake television-streaming app to Spanish-speaking users. Once installed, the app delivers StreamRat, a previously undocumented Android banking trojan capable of granting attackers near-complete control over a victim's device.

The campaign specifically targeted users in Spain and reached an estimated 570,950 Meta accounts across the European Union, showing how effective legitimate advertising platforms can be as a distribution channel for malware. By posing as a popular type of app, the campaign lures users into sideloading software outside official app stores, bypassing the security checks Google Play typically provides.

While technical details of StreamRat's capabilities are still emerging, banking trojans of this type typically abuse Android's accessibility services to monitor screens, intercept SMS messages and one-time passcodes, and perform actions on behalf of the attacker without the user's knowledge. This makes them a serious threat to both personal and business banking activity conducted on mobile devices.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.