Skip to content
StreamRat Trojan Targets Android Users via Malicious Ads

StreamRat Trojan Targets Android Users via Malicious Ads

First seen 21 Sep 2026, 18:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 18:54 UTC
  • StreamRat targets Android users via social media ads impersonating a streaming service.
  • The campaign has potentially affected around 570,000 users through a multi-stage installation process.
  • Malware capabilities include remote control, keylogging, and disrupting internet connectivity.

StreamRat, an Android banking trojan, has been identified in a campaign that impersonates a free streaming service through social media ads. The campaign has potentially reached around 570,000 victims, guiding them through a multi-stage installation process. Once installed, StreamRat exploits Accessibility Services and screen-capture capabilities to gain remote control over devices, enabling keylogging, credential theft, and hidden screen monitoring. Additionally, the malware can disrupt internet connectivity, hindering cloud-based security checks during installation. This sophisticated attack combines malicious advertising, social engineering, and advanced mobile malware techniques, demonstrating a significant threat to Android users. The current status of the campaign suggests ongoing risks for affected users.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-21
StreamRat Trojan identified
Researchers uncovered the StreamRat Android banking trojan distributed through malicious ads, affecting approximately 570,000 potential victims.
Zimperium

More articles in this cluster (2)

Following this threat?

Track StreamRat in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed