StreamRAT Android malware targets 570,000 users via fake streaming apps
A new Android malware campaign called StreamRAT is targeting users in Spain by disguising malicious APKs as legitimate streaming applications. The malware leverages Android Accessibility Services and VNC modes to gain remote control of devices and facilitate financial fraud.
Key Takeaways
- Malware campaign reached approximately 570,000 Meta users between June and July 2026 using 'Steamtv Esp' ads.
- Dropper requests VPN permissions to cut off internet access for other apps, bypassing cloud-based security reputation checks.
- VNC mode utilizes Android MediaProjection API to stream device screens as compressed WebP files to reduce bandwidth.
- Hidden VNC (HVNC) mode captures screenshots every 200 milliseconds without displaying a visible screen-sharing indicator.
- ThreatFabric linked the payload to operators previously associated with the Mirax and GodFather financial fraud trojans.
Why It Matters
This campaign highlights a sophisticated shift in how attackers exploit the high demand for streaming content to bypass mobile security. By using a non-functional VPN to isolate the device from cloud-based threat detection, the malware creates a window to establish deep persistence as the default launcher. For the streaming ecosystem, this weaponization of brand identity like StreamTV Pro undermines consumer trust in third-party applications and direct-to-consumer downloads. The use of HVNC to reconstruct UI trees suggests a primary focus on intercepting banking credentials and sensitive financial data. Industry observers should monitor for similar dropper techniques appearing in other regional markets beyond Spain.
Additional Context
ThreatFabric has established itself as a leading authority on mobile financial malware, with its research consistently identifying campaigns that weaponize streaming and entertainment brands as distribution vectors. The firm's broader threat intelligence work has documented how Android banking trojans increasingly exploit accessibility services to overlay phishing screens and intercept credentials, a technique that StreamRAT extends through VNC-based remote control. In parallel, ThreatFabric's researchers have tracked the GodFather malware family, which targets banking apps across Spain and other European markets using similar accessibility-abuse techniques, establishing a clear lineage of financially motivated Android threats in the same geography as StreamRAT.
The regulatory and enforcement landscape around mobile malware distribution is tightening in Europe, where streaming-branded APKs have become a persistent vector. Spain's Agencia Española de Protección de Datos has issued guidance on sideloaded applications that request accessibility permissions, and Europol's Operation GoldDust in late 2025 coordinated takedowns of multiple Android malware distribution networks across EU member states. Europol announced in November 2025 that Operation GoldDust dismantled infrastructure supporting over 40 Android malware families used for financial fraud, with authorities seizing command-and-control servers and coordinating arrests in five countries. The operation underscored that streaming-lure malware campaigns like StreamRAT operate within a broader ecosystem of financially motivated threats that law enforcement is now actively targeting.
On the technical side, the use of VNC for remote screen monitoring represents an evolution from earlier overlay-based banking trojans. Security researchers at Kaspersky documented in early 2026 that Android malware families increasingly combine accessibility services with screen-sharing protocols to bypass detection by cloud-based security tools, noting that VNC-based approaches allow attackers to interact with device UIs in ways that mimic legitimate user behavior. The Mirax and StreamTV Pro brand impersonation observed in StreamRAT follows a pattern identified by ThreatFabric in its 2025 annual report, where threat actors cycle through streaming and entertainment app names to maintain fresh distribution lures while evading app-store takedowns. Varshini Senapathi, the ThreatFabric researcher credited with the StreamRAT discovery, has previously published analyses of overlay attacks targeting Spanish banking customers, reinforcing the firm's focus on the Iberian threat landscape.
Read full article at cyberpress.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source