A recent analysis uncovered StreamRat, an Android banking trojan distributed through social media ads impersonating a free streaming service. The campaign reached approximately 570,000 potential victims and directs Android users through a multi-stage installation process. Once installed, StreamRat abuses Accessibility Services and screen-capture capabilities to enable remote device control, keylogging, credential-stealing overlays, and hidden screen monitoring. Researchers also found functionality designed to temporarily disrupt internet connectivity, potentially limiting cloud-based security checks during installation. The campaign demonstrates how attackers are combining malicious advertising, social engineering, and advanced mobile malware to achieve full device takeover.
Read the full report here.
© 2026 Zimperium. All Rights Reserved. Privacy Settings Modern Slavery Act Statement