Security1 distinct publisher2 min readPublished
ThreatFabric traced the StreamRat dropper through four ordinary Android permission prompts to an Accessibility grant that hands operators keystrokes, credential overlays and remote control, with no infection count published.
The Watch · Security desk
security
Manic's mesh relay moves stolen data phone to phone, no internet path required1 distinct publisher
product
Poland asks Brussels for a €250M Meta fine it has no power to levy1 distinct publisher
invest
The remedy New Mexico won at trial is the one Meta's $18 billion settlement does not contain1 distinct publisher
product
Pennsylvania's Snap case makes an App Store questionnaire the alleged lie1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
Before fetching the final payload, the dropper asks permission to establish a VPN connection, and once approved it routes device traffic into a nonfunctional interface while excluding itself from that route [9]. Other applications lose connectivity during the install, and the dropper shuts the VPN down after the payload executes so StreamRat can reach its command-and-control server [10]. ThreatFabric assessed that the interruption may reduce online reputation and code-analysis checks, while noting that Google Play Protect retains offline detection for known potentially harmful applications, which limits the technique's effect [11].
Four dialogs stand between the launch of app.apk and that C2 connection: default Home application, VPN, install from unknown sources, and Accessibility [29]. The Home grant returns the victim to the dropper's interface whenever the Home button is pressed [8]. The payload lands in the public Downloads directory as update_{timestamp}.apk and is installed through Android's package installation mechanism [12]. On the delivery side, June 11 to July 3, 2026 is 23 days inclusive [25], so the 570,950 figure works out to roughly 24,800 EU accounts a day [26], and what that figure counts is accounts that saw the creative at least once [2].
Once Accessibility is enabled, operators can capture keystrokes, display credential-stealing overlays, inspect the visible interface, and control the device remotely [14]. Screen capture works two ways. MediaProjection shows a consent dialog and is typically identified by a screen-sharing indicator, and the malware can use Accessibility to interact with that dialog after the grant [15]. The alternative calls the Accessibility takeScreenshot() method, which captures the screen outside the MediaProjection indicator entirely [16].
The StreamRat payload came from a GitHub account that ThreatFabric linked to an earlier Mirax campaign, and the dropper closely resembled the one used in that operation [17]. ThreatFabric named no threat actor [18] and said only that the work came from individuals with prior experience in the Android malware ecosystem [19]. Cleafy described the hosting setup: GitHub releases, different backup links, daily package updates [24]. Two package names and two C2 IPs are published [23]; by that hosting description, the package names have a short shelf life.
No Android version range was published, and applicability is tied to the installation behavior and the requested permissions [22]. The response window is also already closed: the findings were published on September 2, 61 days after the ad stopped serving and 83 days after it started [27][28].
Ranked by verification strength, evidence, and original report placement.
ThreatFabric disclosed a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices.
ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union that saw it at least once.
Totals for infected devices and confirmed victims remain unreported.
The Meta campaign began on June 11, 2026 and ended on July 3, 2026; it was identified in late July 2026; the findings were published on September 2, 2026.
The social-media lure directs an Android user to a specially crafted website that checks the visitor's operating system and displays its download button to Android devices, where the visitor can download a file named app.apk.
After the victim launches the APK, the dropper asks to become the device's default Home application, which returns the victim to its interface whenever the Home button is pressed.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor, restated once
What holds this up is falsifiability: package names, hashes, a download filename pattern and two C2 addresses that any defender can run against telemetry tonight. What holds it back is that all of it arrives from ThreatFabric through a single outlet, the 570,950 reach estimate comes with no shown basis, and Cleafy — the only other researcher present — is quoted from inside ThreatFabric's own report rather than checked against it.
Wide exposure, unmeasured infection
Reach and infection are different numbers and only the first exists: 570,950 EU accounts saw the ad at least once across 23 days, roughly 24,800 a day, while infected devices and confirmed victims are explicitly unreported. Two live C2 addresses and droppers republished daily from GitHub releases point to an operation in service; how many phones ended up on the far end of it is nowhere in this reporting.
Impressions in front, consent prompts behind
The number leading the story counts people who saw an ad; the capability behind it is total device control. Four separate taps sit in between — Home role, VPN, unknown sources, Accessibility — and nobody has published how many users completed them. The Hacker News keeps its caveats in view rather than burying them, so this reads as a lean toward the dramatic end, not a stretch.
Vendor naming, vendor timing
StreamRat is christened by a mobile fraud-detection firm, which is how findings in this category normally reach the world, and the disclosure lands 61 days after the ads stopped serving — comfortable for the discoverer, less useful for anyone chasing live infrastructure. Cleafy's supporting line comes from Cleafy's own report. None of that makes the technical detail wrong; it does mean "new and technically sophisticated" is the seller's phrase, carried without pushback.
Coherent, uncorroborated
The account is internally consistent and specific enough to act on, and its gaps are declared rather than hidden: no named actor, no Android version range, no victim count, Meta placement left open. What we cannot do is cross-check a single element, because one publisher and one primary researcher stand behind all of it.