StreamRat Trojan Targets Spanish Users via Meta Ads

StreamRat Trojan Targets Spanish Users via Meta Ads

First seen 2 Sep 2026, 14:13 UTC Thehackernewswww.threatfabric.com 69.5

Article Content

Browse articles
ThreatCluster

In late July 2026, a new Android banking trojan named StreamRat was identified, targeting Spanish-speaking users through a fake television-streaming campaign on Meta platforms. The malware is distributed via a phishing website that checks the user's operating system before allowing the download of a malicious APK file. Once installed, StreamRat can gain extensive control over the infected device, including keystroke logging and remote access. The campaign reached approximately 570,000 users, primarily in Spain. StreamRat is believed to be developed as a Malware-as-a-Service (MaaS) offering, utilizing advanced techniques such as an Internet-blocking mechanism during installation. ThreatFabric has not attributed the campaign to any specific threat actor. The malware can also be propagated through TikTok, further expanding its reach.

Key Points: • StreamRat targets Spanish-speaking users via Meta ads and TikTok. • The trojan gains extensive control over infected Android devices. • The campaign reached around 570,000 users, primarily in Spain.

Timeline

2026-06-11
Meta ad campaign launched
Cybercriminals initiated a campaign targeting Spanish users with streaming-themed ads on Meta platforms.
ThreatFabric
2026-07-03
Campaign concluded
The advertising campaign reached approximately 570,000 users before being identified.
ThreatFabric
2026-09-02
StreamRat details disclosed
ThreatFabric published an analysis detailing the StreamRat trojan's capabilities and distribution methods.
ThreatFabric