cyberpress.orgยท23 september 2026
StreamRat Android Trojan Turns Fake Streaming Ads Into Full Phone Takeover

security
ThreatFabric
Cyber Security News
StreamRat
ANY.RUN
Mirax banking trojan
Telegram
VPN connection
dropper
Android malware
Android Accessibility permissions
Malware-as-a-Service
command-and-control server
Adler-32 checksums
phishing site
WebSocket-based communications
cyberpress.org
The StreamRat Android trojan targets users through fake streaming ads, leading to full device takeover. Victims are lured to a phishing site offering a TV-streaming app, which installs a dropper linked to the Mirax banking trojan infrastructure. The final payload, StreamRat, is a previously unseen malware family that hijacks Android devices by becoming the default launcher and monitoring user activity. ThreatFabric observed similar campaigns across several countries, using social-media ads to distribute malicious Android apps. StreamRat collects device details, captures user input, and communicates with a command-and-control server, indicating a potential Malware-as-a-Service operation.