StreamRat Malware Poses as Streaming App to Hijack Android Devices
A new Android malware campaign, StreamRat, uses social media ads for a fake streaming service to trick users into installing an app that grants attackers remote control and access to sensitive data.

Cybercriminals are luring Spanish-speaking Android users with the promise of free streaming content, only to deliver the StreamRat malware. This sophisticated threat operates by disguising itself as a legitimate streaming application, exploiting social media advertising channels to reach its targets. The campaign, which saw significant ad reach between June 11 and July 3, 2026, targeted approximately 570,000 Meta users, highlighting the broad potential impact of this deceptive tactic.
Once installed, StreamRat leverages critical Accessibility permissions, a feature designed to aid users with disabilities, to gain extensive control over the infected device. This includes the ability to capture sensitive information such as passwords, record the device's screen, and execute remote commands, effectively turning the user's phone into a remotely controlled tool for attackers. The malware's capabilities extend to displaying convincing fake login pages for banking applications, aiming to pilfer financial credentials.
The infection process is carefully staged to bypass user suspicion. Initial social media advertisements direct users to a website that detects their operating system and presents tailored installation instructions, often encouraging users to enable installations from unknown sources. A dropper application is downloaded first, which attempts to replace the device's default home screen. This initial stage is crucial for guiding the user through the subsequent steps, including granting the necessary Accessibility permissions.
After obtaining the required permissions, StreamRat can monitor on-screen activity, capture keystrokes, and perform automated taps and swipes. It also gathers information about installed applications, enabling attackers to strategically deploy fake login overlays for banking or other sensitive applications. The malware offers two methods for screen monitoring: one utilizing Android's standard screen-sharing permission and another that repeatedly captures screenshots via Accessibility without a visible indicator, making its surveillance more covert.
Beyond data theft, StreamRat employs techniques to conceal its malicious activity. It can render the screen black or display a fake system update message while an attacker operates the device in the background. Furthermore, the malware can interfere with network connectivity for other applications during its installation phase, potentially disrupting security checks that rely on cloud-based analysis, while maintaining its own communication channels to command-and-control servers.
While researchers have not yet published definitive figures on the number of compromised devices or successful financial thefts, the scale of the advertising campaign suggests a significant potential for widespread infection. The methods employed by StreamRat, including the abuse of Accessibility permissions and the use of deceptive social media lures, are becoming increasingly common tactics in the Android malware landscape.
Users are strongly advised to exercise caution when downloading applications from sources outside official app stores, especially those promoted through social media advertisements. Any application requesting extensive permissions like Accessibility, screen recording, or VPN access should be viewed with suspicion. Organizations should implement policies to monitor employee devices for unauthorized installations and unusual permission changes.