-
A new Android banking trojan named StreamRat spread through fraudulent Meta streaming ads targeting EU users.
-
The malware uses a two-stage dropper that breaks internet connections temporarily to bypass online security checks during payload setup.
-
StreamRat abuses Accessibility Services to log keystrokes, stream screens, and gain complete remote device control.

Cybersecurity specialists have discovered a new perilous Android menace that affects mobile users located across Europe. The perpetrators of the operation used fabricated streaming ads displayed on well-known social media channels to distribute malware.
The malicious software tricks users into giving up full control over their mobile devices. Security teams have traced the primary origin of this attack campaign to fraudulent promotions on Meta.
Social Media Ads Spread Dangerous Mobile Threats
The ThreatFabric security specialists uncovered this malicious operation aimed at mobile consumers who speak Spanish. The criminals constructed advertisements promising free TV streaming services to attract unsuspecting people.
The ads appeared prominently on the platforms of Meta like Facebook and Instagram. Reports state the malicious ads affected nearly 570,950 accounts in the European Union. Researchers also spotted code references pointing toward TikTok as another potential promotion channel.
A campaign targeting Brazilian crypto users spread Eternidade Stealer via WhatsApp, using fake government, delivery, and investment lures to steal data from platforms like Binance, Coinbase, MetaMask, and Trust Wallet.
When users clicked on the social media lures, the web link pointed them to a specialized landing site. This portal checked the operating system of the device of the visitor automatically. The site then offered a direct Android Package download button if it detected an Android system. Victims downloaded a file named app.apk onto their mobile phones. The initial dropper application quickly started its setup routine once launched.
The active campaign ran from June 11 to July 3, this year, before security researchers identified it later that month. Investigators published detailed analysis reports on September 2.
The findings linked the payload setup to a GitHub account previously connected to the Mirax malware family. Security researchers at Cleafy had tracked that earlier operational infrastructure. The close technical ties show that experienced developers created this new strain.
How the Stealthy Dropper Tricks Android Protection
The dropper app uses clever tricks to hide its true intentions during setup. First, it asks the user to make it the default Home app on the device. This setting routes the user right back to the app screen whenever they hit the Home button. Next, the dropper requests permission to establish a local Virtual Private Network connection.
Accepting the VPN request triggers an intentional network breakdown on the device. The fake network interface routes all mobile internet traffic into a nonfunctional loop. Meanwhile, the dropper excludes its own traffic from this restriction.
Other applications on the phone suddenly lose internet access during this process. ThreatFabric noted that breaking the internet connection disrupts live security analysis checks.
Eventually, the dropper fetches the main payload file from remote storage servers. It saves the malicious file into the public Downloads directory as an update file. The application then prompts the victim to allow app installations from unknown sources.
Once approved, the dropper uses the package installation framework of Android to deploy the main StreamRat software. It shuts down the fake VPN connection right after the payload launches. This move restores regular network connectivity so StreamRat can reach its command-and-control server.
Security services like Google Play Protect still maintain local offline detection capabilities for known malicious files. Consequently, the temporary internet disruption cannot fully bypass every protective shield on the device.
Total Device Takeover via Accessibility Abuse
StreamRat relies heavily on system permissions to take complete control of a target device. Immediately after launching, the payload demands access to Accessibility Services. Granting this request gives the malware total authority to interact with the device interface.
The operators can log user keystrokes, view active screen layouts, and launch fake overlay screens, these deceptive overlays pop up over legitimate banking applications to harvest login credentials.
The trojan captures live screen content using two different system methods. First, it calls the Android MediaProjection API to capture high-quality video frames. This feature normally triggers a system consent dialog and displays a screen-sharing indicator icon. However, StreamRat uses its Accessibility access to click the approval dialog automatically without real user input.
Additionally, the malware uses the native takeScreenshot method as a secondary capture option. This second method lets operators record screen activity without triggering the visible media indicator.
StreamRat compresses captured images down significantly to save bandwidth during live streaming sessions. The tool drops frame quality and scales down image dimensions before sending data to remote command servers.
The attacker can control the device remotely while hiding their movements behind dark screen covers. StreamRat can display a pitch-black layer over ninety-eight percent of the screen.
It can also show a fake system update screen while performing unauthorized actions in the background. These visual covers block real user touches, leaving attackers free to navigate financial apps silently.
Preventing Mobile Malware Infections and Safeguarding Data
Mobile banking trojans can seriously threaten the privacy and financial security of a person. Cybercriminals are constantly developing and improving these programs to circumvent the standard protective measures for devices.
This means users must exercise caution when obtaining software that is not available on official application stores. Also, by downloading apps from websites that are not well-known significantly they increase the chance of malware infection.
Mobile users should inspect every permission request carefully during software installation. A simple streaming video app never requires access to deep administrative systems.
Users should cancel installation instantly if a basic utility requests Accessibility permissions. Official updates and security applications such as Malwarebytes can identify modern cyber threats at an early stage.
Besides, internet users should be wary of ads on social networks that promote free premium services. Attackers frequently purchase social ad spaces to target broad audiences quickly. Checking app reviews, verifying developer credentials, and relying on official distribution channels remain effective defense habits.