StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTok

StreamRat Android Banking Trojan Spreads via Fake (TL-2026-2312), also tracked as Steamtv Esp., is a high-severity malware campaign, first published 2026-09-03. It has no confirmed attribution, affects Google Android, maps to 16 MITRE ATT&CK techniques (T1407, T1417, T1417.001), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-2312

Threat ID
TL-2026-2312
Also known as
Steamtv Esp.
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-03
Last reviewed
2026-09-03
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial services, consumer retail banking customers
Target regions
spain, European Union
Detection rules
9
Indicators of compromise
18

Malware and tooling in StreamRat Android Banking Trojan Spreads via Fake

Malware and tooling: Godfather, Mirax, StreamRat, Android/PUP.Agent.ACR02DB0614H7

StreamRat, a newly discovered Android banking Trojan and infostealer built on a Malware-as-a-Service (MaaS) backend, is being distributed through fake free-TV-streaming-service ads on Meta (Facebook/Instagram) and TikTok, primarily targeting Spanish-speaking users in Spain. A Meta campaign named "Steamtv Esp." ran June 11 to July 3, 2026 and reached roughly 570,000-570,950 users; once sideloaded, StreamRat abuses Accessibility Services, MediaProjection, and Device Administrator privileges to deliver credential-stealing overlays, keylogging, HVNC/VNC-style screen streaming, and full remote device control.

How StreamRat Android Banking Trojan Spreads via Fake works

ThreatFabric researchers uncovered StreamRat, an Android banking Trojan/infostealer distributed through malvertising on Meta and TikTok impersonating a free TV-streaming service. The Meta campaign, internally named "Steamtv Esp.," ran from June 11 to July 3, 2026 and reached an estimated 570,000-570,950 accounts in the EU, overwhelmingly Spanish-speaking users in Spain; identical banner creative was also run on TikTok.

Victims who click the ad are sent to a lure site that fingerprints the visitor's OS (blocking non-Android devices) and referral source (Instagram, TikTok, Facebook, or generic browser), then serves referrer-tailored install instructions via a page named r1edmi.html. The victim is guided to enable installation from unknown sources and download an initial APK (app.apk). The APK is a dropper built from a set of interconnected HTML/JavaScript pages (Index.html, Set_launcher.html, Vpn_required.html) rather than compiled native obfuscation. The dropper coerces the victim into three escalating grants: (1) setting the dropper as the default/HOME launcher, so pressing the Home button re-displays the dropper's social-engineering flow; (2) establishing a Device VPN permission used to create a deliberately non-functional VPN that blocks Internet access for every other app on the device (excluding the dropper itself), degrading other security tools' ability to perform cloud/online-reputation checks during installation; and (3) downloading and installing a second-stage payload (named update_{timestamp}.apk) that requests Accessibility Services. Once Accessibility access is granted, the dropper uninstalls/removes itself, and the final payload becomes the persistent backdoor.

Two payload samples were identified: package io.base.one887 (app label "StrεαmTV Pro") and package io.meat.hint (app label "Sistema de vídeo"). Malwarebytes detects the family generically as Android/PUP.Agent.ACR02DB0614H7.

Once active, the bot communicates with hardcoded C2 servers (45.147.28.59 and 193.32.2.245) over a WebSocket-based, binary RPC-like protocol: the initial upgrade request carries custom X-Device-Id / X-Device-Model / X-Api-Level headers, and subsequent frames use a 2-byte opcode + 4-byte command ID + payload format (bot responses mirror with a 4-byte command ID + 1-byte status + 4-byte length + payload). The bot supports 37+ commands spanning shell execution, device lock/wake, VNC-mode and HVNC-mode screen capture, an Accessibility Node Viewer for remote UI inspection/control, overlay management, arbitrary app launching, PIN/pattern extraction and remote device unlock, Accessibility-based keylogging, and fake notification generation.

Credential theft is delivered through a foreground-app-monitoring loop: the bot sends maintenance_check and injection_check requests containing the current foreground package name, and the C2 responds with an HTML overlay (saved client-side as <package_name>.html) rendered in a WebView with a JavaScript bridge enabled. Overlay types include a black screen covering ~98% of the display to mask fraudulent activity from the victim, a fake system-update screen used as a distraction cover, and interactive injection overlays used to harvest typed data. To reduce backend load and limit detectable signal, the malware computes Adler-32 checksums over serialized AccessibilityNodeInfo UI-tree dumps and only reports changed states.

Control-panel code analysis indicates StreamRat was built as a Malware-as-a-Service offering: the backend implements user/supervisor/admin role separation for multiple simultaneous operators and includes a dedicated builder for customers to generate customized droppers and payloads. ThreatFabric ties the same threat actor to at least two prior Android financial-malware families -- GodFather and StreamRat's most direct predecessor, Mirax (an April 2026 campaign). The StreamRat payload was retrieved from a GitHub repository belonging to the same developer account previously used to distribute Mirax, with daily package/release updates, and the StreamRat dropper's design closely mirrors Mirax's dropper architecture, indicating iterative reuse rather than a clean-sheet build. ThreatFabric did not attach a named threat-actor label to the operator.

MITRE ATT&CK techniques used in TL-2026-2312

Defense Evasion

T1407 Download New Code at Runtime; T1629 Impair Defenses; T1630 Indicator Removal on Host; T1655 Masquerading

Credential Access

T1417 Input Capture; T1417.001 Keylogging; T1417.002 GUI Input Capture

Discovery

T1424 Process Discovery

Command and Control

T1437 Application Layer Protocol; T1437.001 Web Protocols; T1544 Ingress Tool Transfer

Initial Access

T1456 Drive-By Compromise

Collection

T1513 Screen Capture

Impact

T1516 Input Injection

Privilege Escalation

T1626 Abuse Elevation Control Mechanism; T1626.001 Device Administrator Permissions

Affected products and versions in StreamRat Android Banking Trojan Spreads via Fake

  • Google — Android
    Vulnerable versions: Any Android version exposing the Accessibility Service, MediaProjection, Device Administrator, and default-launcher (HOME role) APIs abused by StreamRat

Remediation for StreamRat Android Banking Trojan Spreads via Fake

Immediate actions

  • Block outbound traffic to StreamRat C2 IPs 45.147.28.59 and 193.32.2.245 at perimeter/DNS/firewall layers.
  • For any device suspected of installing io.base.one887 ("StrεαmTV Pro") or io.meat.hint ("Sistema de vídeo"), disconnect it from Wi-Fi/mobile data immediately to cut C2 access.
  • Uninstall the malicious app; if it was set as the default launcher, reset the default HOME app via Android Settings > Apps > Default apps before/while removing it.
  • Revoke Accessibility Services, Device Administrator, and Default App permissions granted to the malicious package via Settings before uninstalling.
  • Change passwords for any banking, email, and social-media accounts accessed on the compromised device, and contact affected financial institutions to flag potential account takeover/fraud.

Workarounds

  • Only install Android apps from the Google Play Store; avoid APKs offered via advertisements, direct-download links, or messages from strangers.
  • Before installing, verify the developer's identity, review history, and install counts; be suspicious of new/low-review-count "free streaming" apps.
  • Treat any app requesting Accessibility Services, Device Administrator, MediaProjection (screen sharing), or default-launcher/HOME-app status without a clear functional need as a red flag and decline the request.
  • Be suspicious of any installer flow that instructs disabling security warnings or granting a VPN permission as a precondition for using an unrelated streaming app.

Longer-term hardening

  • Deploy a mobile threat defense (MTD) or EDR solution capable of behavioral detection of Accessibility-Service and MediaProjection abuse, not just signature matching.
  • Enable and enforce Google Play Protect scanning and block sideloading (installation from unknown sources) via MDM/EMM policy on managed devices.
  • Use DevicePolicyManager.setPermittedAccessibilityServices (or equivalent EMM control) to restrict which apps may register as Accessibility Services on managed fleets.
  • Monitor ad-platform brand/keyword abuse (fake streaming-service creative) and report malicious Meta/TikTok ad campaigns for takedown.

Timeline of StreamRat Android Banking Trojan Spreads via Fake

  • ThreatFabric-tracked Mirax Android banking-trojan campaign runs (April 2026); its dropper architecture and GitHub release infrastructure closely resemble and are directly reused by StreamRat's dropper.
  • Meta advertising campaign "Steamtv Esp." begins, running fake free TV-streaming-service ads on Facebook and Instagram targeting Spanish-speaking users, primarily in Spain; identical banner creative also appears on TikTok.
  • The "Steamtv Esp." Meta ad campaign concludes, having reached an estimated 570,000-570,950 Meta accounts across the EU.
  • ThreatFabric researchers identify and begin technical analysis of the StreamRat campaign, malware, and MaaS backend (reported as occurring in late July 2026).
  • The Hacker News, GBHackers, and CyberSecurityNews publish coverage summarizing ThreatFabric's StreamRat findings and IOCs for a broader security audience.
  • ThreatFabric publishes "Uncovering StreamRat: From Meta Ads to Full Device Takeover," detailing the dropper chain, WebSocket C2 protocol, bot command set, MaaS backend, and IOCs.
  • Malwarebytes Labs publishes coverage of the StreamRat campaign, detecting the payload generically as Android/PUP.Agent.ACR02DB0614H7 and issuing consumer-facing remediation guidance.

Sources cited for StreamRat Android Banking Trojan Spreads via Fake

More in malware

Detection coverage for TL-2026-2312

As of 2026-09-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2312 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats