StreamRat trojan rides fake TV apps to take over Android devices

ThreatFabric details StreamRat, an Android trojan pushed through fake TV streaming ads that can seize device control.

CSBadmin
1 Min Read

A newly documented Android trojan named StreamRat is being pushed through fake television-streaming ads on Meta and can hand operators near-complete control of infected phones. ThreatFabric says the Spanish-language campaign reached an estimated 570,950 Meta accounts in the European Union between June 11 and July 3.

The social media lure sends Android users to a site that serves an app.apk file. The dropper asks to become the default home app, then requests VPN permission that briefly cuts the device’s internet while the real payload installs from a GitHub release. After StreamRat runs, it demands Accessibility access, unlocking keystroke capture, credential-stealing overlays, screen capture, and remote control.

The malware can record the screen through Android’s MediaProjection API or quietly via Accessibility-based screenshots that avoid the usual sharing indicator. ThreatFabric did not attribute the campaign to a named actor but says the dropper closely resembles one used in an earlier Mirax operation, and researchers found the same lure family on TikTok.

Play Protect retains offline detection for known harmful apps, but sideloaded installs bypass store review. Users should stop any installation when a streaming app asks for system controls unrelated to streaming. Infected-device totals were not published.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.