cyberpress.orgยท23 september 2026

StreamRat Android Trojan Turns Fake Streaming Ads Into Full Phone Takeover

Image for the article: StreamRat Android Trojan Turns Fake Streaming Ads Into Full Phone Takeover
Image via cyberpress.org

The StreamRat Android trojan targets users through fake streaming ads, leading to full device takeover. Victims are lured to a phishing site offering a TV-streaming app, which installs a dropper linked to the Mirax banking trojan infrastructure. The final payload, StreamRat, is a previously unseen malware family that hijacks Android devices by becoming the default launcher and monitoring user activity. ThreatFabric observed similar campaigns across several countries, using social-media ads to distribute malicious Android apps. StreamRat collects device details, captures user input, and communicates with a command-and-control server, indicating a potential Malware-as-a-Service operation.