Malicious Android Trojan ‘StreamRAT’ Hijacks Devices via Fake Streaming Ads on Meta and TikTok
A newly uncovered Android banking trojan dubbed StreamRAT is weaponising legitimate Android features to seize full control of victims' phones, security researchers reported. The malware is being pushed through counterfeit free‑TV streaming advertisements that appear on Meta platforms and TikTok, targeting users who speak Spanish.
The operation, tracked by researchers under the name “Steamtv Esp.,” has reportedly reached an estimated 570,000 Meta users since June. By masquerading as a legitimate streaming service, the ads entice users to download a seemingly innocuous app, which then silently activates Android’s Accessibility service, MediaProjection API and a hidden virtual network computing (HVNC) component. Together these tools let the trojan capture screen contents, record keystrokes, and even inject fraudulent transactions into banking apps.
StreamRAT’s abuse of the Accessibility service is notable because the permission grants the app the ability to read and interact with the user interface across the entire device. When combined with MediaProjection, which was originally designed to enable screen sharing and recording, the malware can mirror the victim’s screen in real time without displaying any obvious indicator. The HVNC layer then streams this view to remote operators, effectively giving them a remote desktop experience on a mobile device.
Experts say the campaign reflects a broader trend of threat actors exploiting the trust users place in free streaming content. Platforms such as Meta and TikTok have become fertile ground for these lures, as the short‑form video format allows malicious ads to blend with legitimate promotions. The focus on Spanish‑speaking audiences suggests the operators are pursuing a geographically or linguistically defined profit motive, likely aiming at banking credentials from regions where mobile banking is prevalent.
While the exact financial impact of StreamRAT is still being quantified, the potential for large‑scale theft is significant. Banking trojans that gain unfettered access to a device can bypass two‑factor authentication, intercept one‑time passwords, and manipulate transaction flows. Users who unknowingly install the fake streaming app may see unauthorized withdrawals or fraudulent purchases appear on their statements.
Security firms advise Android users to scrutinise any app that requests Accessibility or screen‑recording permissions, especially when the request comes from an unfamiliar source. Keeping the operating system and installed applications up to date, using reputable antivirus solutions, and limiting app installations to official app stores are standard mitigations. Platforms hosting the malicious ads have been notified, and removal efforts are underway, though the rapid turnover of ad content can make enforcement challenging.
Going forward, researchers will monitor the “Steamtv Esp.” campaign for signs of evolution, such as additional payloads or new distribution channels. The incident underscores the need for heightened vigilance among mobile users and a coordinated response from social media platforms to curb the spread of deceptive advertising that serves as a gateway for sophisticated malware.
Comments (0)
Be the first to comment.
Join the discussion