Fake TV Streaming Ads on Facebook Pushed a New Android Banking Trojan to Spanish Users

StreamRat, spread through Meta ads that reached more than half a million EU accounts, hands attackers near-total control of the phone it lands on.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit living room with a wall-mounted smart TV glowing pale blue, a small black streaming box on
Share

Key points

  • Researchers at ThreatFabric have named a new Android banking trojan StreamRat, a piece of malicious software that hides inside what looks like a free TV streaming app.
  • The criminals promoted the fake app through paid ads on Meta's platforms, mostly Facebook, targeting Spanish speakers in Spain.
  • The ad campaign reached an estimated 570,950 accounts across the European Union before being flagged.
  • Once installed, StreamRat can read screens, tap buttons, and steal banking logins, giving operators near-complete remote control of the phone.
  • The lure was a fake television-streaming service, chosen because free-TV apps get clicked on without much thought.

A new Android banking trojan is doing the rounds in Spain, and the delivery route is depressingly familiar: paid ads on Facebook and Instagram.

The malware is called StreamRat. Researchers at Dutch mobile-fraud firm ThreatFabric say the operators dressed it up as a free television streaming app, then bought ads on Meta's platforms to push it at Spanish-speaking users. The campaign reached roughly 570,950 accounts inside the European Union before it was spotted.

Once a victim installs the app, the attackers get something close to full remote control of the phone. That is the important bit for anyone who does their banking on a handset, which is most of us.

What does StreamRat actually do once it's on your phone?

It watches, taps, and steals. StreamRat is a remote access trojan, meaning software that lets a criminal operate the phone as if they were holding it. It can read what is on screen, press buttons on its own, and pull out passwords and banking codes.

In practice, the failure mode here is Android's accessibility permissions. These are the same permissions that let screen readers help blind users. If a malicious app tricks you into granting them, and free-app installers are very good at that dance, it can see every tap and inject its own. Banking apps, two-factor codes, wallet apps, all of it becomes readable.

The first reporting on StreamRat came via The Hacker News, drawing on ThreatFabric's analysis.

How did the criminals get their app in front of so many people?

They paid for it. That is the uncomfortable part. Rather than hacking anything clever, the operators simply bought ads on Meta and let the algorithm find people who click on free-TV promos.

Meta's ad review is supposed to catch this. It does not, reliably. One thing the post-mortem will say, and has said in every other version of this story from the last two years, is that ad-network moderation at scale is a losing game against a determined seller who keeps rotating accounts and creatives.

What the campaign looked like

Detail Figure
Malware name StreamRat
Platform targeted Android
Ad platform used Meta (Facebook, Instagram)
EU accounts reached 570,950
Main country targeted Spain
Disguise Fake TV streaming app

Should ordinary phone users be worried?

Only if you install apps from outside the Google Play Store, which is exactly what this ad campaign talked people into doing. The safer habit is boring: install apps only from the Play Store, and treat any ad that promises free premium TV as a scam by default.

A few practical steps if you clicked something like this recently:

  • Open Settings, then Apps, and remove anything you do not remember installing, especially anything asking for Accessibility access.
  • Check your bank's app for logins or transfers you did not make, and call the bank if anything looks off.
  • Change your banking password from a different device, not the phone you suspect.
  • Run Google Play Protect from the Play Store's menu, which scans installed apps.

This is not the last Meta-ad malware campaign we will write about this year. Banking trojans have discovered marketing budgets, and the cost of a working install is cheaper than the payout from a drained account.

Operational takeaway: if an ad is selling you free TV, the product is you.

© 2026 Threat Vectr