StreamRat Android Trojan Hits 570,000 Meta Users via Fake Streaming Ads
A sophisticated malvertising campaign targeting Spanish speakers grants attackers near-complete control over infected devices.
A new Android banking trojan known as StreamRat has infected hundreds of thousands of users through deceptive advertisements on Meta platforms. The campaign, discovered by cybersecurity firm ThreatFabric, leverages fake television-streaming services to lure victims into installing malware that grants operators near-complete control over the compromised device.
According to ThreatFabric, one specific campaign reached approximately 570,000 Meta users between June 11 and July 3, 2026. The attackers targeted Spanish-speaking users, primarily located in Spain, by promoting fraudulent streaming apps. Once installed, the trojan utilizes Android's Accessibility Services and MediaProjection to seize control of the device, allowing attackers to monitor activity and manipulate the system.
The Rise of Malvertising
This attack is part of a growing trend where cybercriminals use legitimate advertising networks—including Meta and TikTok—to distribute malicious software. By utilizing trusted platforms, attackers can bypass traditional security filters that typically block suspicious links or unknown sources. In this instance, the lure of free, high-quality streaming content served as the primary hook to convince users to bypass security warnings and install the StreamRat payload.
Industry Implications
The scale and depth of the StreamRat infection highlight a critical vulnerability in how users interact with social media advertising. Because the malware gains such extensive permissions, the risk extends far beyond simple data theft. Attackers can potentially access sensitive financial information, intercept two-factor authentication codes, and steal personal credentials in real-time. For the hundreds of thousands of potential victims across the European Union, this represents a total compromise of device security and personal privacy.
What to Watch
Security researchers continue to monitor the evolution of StreamRat and similar banking trojans that exploit system-level permissions. While the primary target of this campaign was Spanish speakers, the infrastructure used for these Meta ads suggests a scalable model that could be adapted for other languages or regions. Users are advised to avoid downloading applications from third-party links in social media ads and to strictly limit the granting of Accessibility Services permissions to trusted, verified applications.