<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control]]></title><description><![CDATA[<p dir="auto">Researchers have uncovered a new Android banking trojan dubbed <strong>StreamRat</strong>, which was distributed to Spanish-speaking users through malicious advertisements on Meta. The campaign, which used a fake television-streaming app as a lure, was primarily aimed at audiences in Spain and reportedly reached an estimated <strong>570,950 Meta accounts</strong> across the European Union.</p>
<p dir="auto">According to ThreatFabric, the ad campaign was designed to appear legitimate, enticing users to download a streaming service that actually carried the malicious payload. Once installed, <strong>StreamRat</strong> grants its operators extensive control over the infected device, functioning as a full-featured remote access tool (RAT). This includes the ability to steal credentials, intercept two-factor authentication codes, read and send SMS messages, and even capture screen content in near real-time.</p>
<p dir="auto">The trojan's capabilities go beyond typical banking malware, as it can also manipulate device settings, install additional payloads, and potentially lock users out of their own devices. The campaign underscores a growing trend where malware distributors abuse legitimate advertising networks to target specific linguistic and geographic groups, bypassing traditional email-based phishing vectors.</p>
<p dir="auto">For Android users, especially those in Spanish-speaking regions, this serves as a reminder to only download applications from the official Google Play Store and to scrutinize app permissions carefully.</p>
<ul>
<li><strong>Target vector</strong>: Malicious Meta ads promoting a fake TV streaming app.</li>
<li><strong>Primary region</strong>: Spain / European Union.</li>
<li><strong>Impact</strong>: Full device takeover, credential theft, SMS interception, and screen capture.</li>
<li><strong>Distribution</strong>: Third-party APK downloads (not via official store).</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your organization taken steps to block sideloaded APK installations on managed devices, or are you still relying on user awareness alone to prevent such infections?</p>
]]></description><link>https://xploitlk.com/topic/235/meta-ads-push-streamrat-android-trojan-that-can-gain-near-complete-device-control</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 05:39:01 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/235.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 06 Sep 2026 08:30:36 GMT</pubDate><ttl>60</ttl></channel></rss>