StreamRat Android banking trojan with remote-control capabilities
Malware Activity
Summary
Hide ▲
Show ▼
The StreamRat Android banking trojan is being pushed through fake streaming ads on Meta and can yield near-complete device control, raising the risk of credential theft and remote abuse on infected Android phones. The operation focused on Spanish-speaking users and reached an estimated 570,950 Meta accounts in the EU. Infection required victims to sideload an APK and approve intrusive permissions. Once Accessibility access was granted, the malware could capture keystrokes, show credential-stealing overlays, take screenshots, and control the device remotely.
Related Happenings
StreamRat Meta ad campaign targeting Spanish-speaking users
Campaign
H score48
First: 02.09.2026 15:22
Last: 02.09.2026 15:22
Sources 1
How related:
ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported.
About this happening:
A Meta ad campaign is pushing StreamRat to Spanish-speaking users, expanding exposure to an Android banking trojan that can steal credentials and take over devices. Th...
StreamRat Meta ad campaign targeting Spanish-speaking users
CampaignHow related: ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once, with totals for infected devices and confirmed victims remaining unreported.
About this happening: A Meta ad campaign is pushing StreamRat to Spanish-speaking users, expanding exposure to an Android banking trojan that can steal credentials and take over devices. Th...
Manic Android malware activity with offline relay exfiltration
Malware Activity
H score29
First: 20.08.2026 13:02
Last: 20.08.2026 13:02
Sources 1
About this happening:
Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
Manic Android malware activity with offline relay exfiltration
Malware ActivityAbout this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware Activity
H score20
First: 12.08.2026 17:30
Last: 12.08.2026 17:30
Sources 1
About this happening:
WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware ActivityAbout this happening: WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
RedWing Android spyware rented through Telegram
Malware Activity
H score21
First: 08.07.2026 18:30
Last: 08.07.2026 18:30
Sources 1
About this happening:
The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android spyware rented through Telegram
Malware ActivityAbout this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
Timeline
-
02.09.2026 15:22 1 articles · 1h ago
Meta campaign begins pushing StreamRat through fake streaming ads
Campaign Scope UpdateOn June 11, 2026, a fake television-streaming campaign on Meta begins targeting Spain with StreamRat, an Android banking trojan delivered through a lure that directs Android users to a crafted website and a sideloaded APK.
Show sources
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control — thehackernews.com — 02.09.2026 15:22
-
02.09.2026 15:22 1 articles · 1h ago
Meta campaign ends after promoting StreamRat in Spain
Campaign Scope UpdateOn July 3, 2026, the Meta campaign ends after running against Spanish-speaking users in Spain and reaching an estimated 570,950 Meta accounts in the European Union that saw the ad at least once.
Show sources
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control — thehackernews.com — 02.09.2026 15:22
-
02.09.2026 15:22 2 articles · 1h ago
ThreatFabric publishes StreamRat Android banking trojan analysis
Initial DisclosureThreatFabric discloses StreamRat, a new Android banking trojan that was promoted through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. The analysis says the campaign focused on Spain, reached an estimated 570,950 Meta accounts in the EU, was identified in late July 2026, and was not attributed to a named threat actor.
Show sources
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control — thehackernews.com — 02.09.2026 15:22
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control — thehackernews.com — 02.09.2026 15:22