The promise of free television has become a snare for Android owners. ThreatFabric has uncovered a new banking trojan, StreamRat, disseminated among Spanish-speaking users through advertisements across the Meta ecosystem and TikTok. A single campaign reached roughly 570,000 Meta accounts in the European Union.
The advertisements led to the website of a fictitious streaming-television service. The page inspected the operating system and revealed a download button solely to Android owners. Visitors were invited to download an APK file and permit installation from unknown sources. The instructions shifted according to where the visitor had arrived from, whether Facebook, Instagram, TikTok, or a browser.
A Dropper That Hijacks the Home Screen and Severs Connectivity
The first application appointed itself as the Android home screen, so pressing the Home button returned the user to the installation window. The dropper then activated a non-functional VPN connection and stripped all other programs of internet access. This ploy could hinder cloud-based defenses from inspecting the second APK, though Google Play Protect’s offline scanning continued to operate.
Once installed, StreamRat requested access to Android’s Accessibility Services and connected to its command-and-control server. The trojan logged keystrokes, monitored open applications, captured the screen, and relayed it to the operator. Counterfeit windows layered over banking apps intercepted logins and other entered data, while a covert mode permitted screen observation with no visible broadcasting indicator.
Near-Complete Remote Control in the Operator’s Hands
The operator could press buttons, perform gestures, launch applications, fabricate notifications, lock the screen, and unlock the smartphone with an intercepted PIN or pattern. A black overlay or a bogus update window concealed these clandestine actions. As ThreatFabric’s researchers detailed in their analysis, the control panel houses builders for both the dropper and the trojan, alongside distinct user roles, pointing unmistakably to a Malware-as-a-Service model.
How to Protect Yourself
The number of infected devices and confirmed victims remains unknown. Android owners are advised not to install APK files from advertisements. Moreover, they should halt installation whenever a television-viewing app asks to appoint itself the home screen, create a VPN, download other programs, or command Accessibility Services. Following any suspicious installation, one should remove the application, review permissions, and change banking credentials from a clean device.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.