New Android Trojan 'StreamRat' Targets Spanish-Speaking Users via Fake Streaming Ads
AI-generated from multiple sources. Verify before acting on this reporting.
MADRID, Sept. 2 — Cybersecurity researchers from ThreatFabric disclosed the existence of a new Android banking trojan named StreamRat, which is being distributed through fraudulent television-streaming campaigns targeting Spanish-speaking users across Spain and the European Union. The malicious software grants operators near-complete control over infected devices, posing a significant threat to financial security and personal data.
The campaign utilizes deceptive advertisements on social media platforms Meta and TikTok, promising free access to premium television content. When users click on these links, they are directed to download what appears to be a legitimate streaming application. Instead, the installation triggers the deployment of StreamRat, which operates silently in the background. Once active, the trojan bypasses standard Android security measures, allowing attackers to execute commands, access sensitive files, and monitor user activity without detection.
ThreatFabric analysts identified the malware's capability to intercept banking transactions and steal credentials, a hallmark of modern financial espionage tools. The researchers noted that the trojan is specifically engineered to evade mobile security software, making it difficult for standard antivirus applications to flag the infection immediately after installation. The distribution method highlights a shift in cybercriminal tactics, leveraging popular social media channels to reach a broad audience with high engagement rates.
The attack vector relies heavily on language-specific targeting, with all promotional material and landing pages presented in Spanish. This precision suggests that the operators are focusing their efforts on regions where Spanish is the primary language, including Spain and parts of Latin America, though the initial discovery centers on activity within the European Union. The malware's ability to request extensive permissions during installation allows it to override device settings, potentially enabling remote access to cameras, microphones, and location data.
Security experts warn that the combination of social engineering and sophisticated malware creates a dangerous environment for mobile users. Unlike previous banking trojans that required physical interaction or direct links from compromised websites, StreamRat exploits the trust users place in popular advertising networks. The researchers emphasized that the campaign is currently active and expanding, with new ad variations appearing daily to circumvent platform takedown efforts.
As of Tuesday, no specific financial losses have been publicly attributed to the StreamRat campaign, though the potential for widespread damage remains high given the malware's capabilities. Authorities in Spain and EU member states have not yet issued a formal alert regarding the specific trojan, leaving users reliant on general cybersecurity advisories. The operators behind the campaign remain unidentified, and their ultimate objectives beyond financial theft are unclear. Questions persist regarding the scale of the infection and whether other social media platforms are being utilized to distribute the malicious application.