Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
- ID
- 20699
- Status
- summarized
- Published
- 02 Sep 2026, 8:22 PM
- Fetched
- 02 Sep 2026, 10:17 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/meta-ads-push-streamrat-android-trojan.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.0
- Created
- 02 Sep 2026, 10:21 PM
- Tags
- Audience
- developerssaas_founders
What happened
ThreatFabric disclosed StreamRat, a sophisticated Android banking trojan promoted through Meta ads targeting Spanish-speaking users in Spain, reaching an estimated 570,950 EU Meta accounts. The malware gains near-complete device control by chaining permissions: becoming the default Home app, establishing a VPN, sideloading a payload, and requesting Accessibility access to capture keystrokes, display overlay attacks, and enable remote C2 control.
Why it matters
This is a consumer-targeted malvertising campaign with no direct impact on AI/ML tooling, developer infrastructure, or SaaS operations. The only tangential takeaway for founders running Meta ads is that malvertising on the platform remains active, but there is no action to take beyond standard ad-platform hygiene.
Discussion angle
Brief mention only: Meta's ad platform is being abused to distribute mobile malware at scale, which is worth noting if your startup targets mobile users in affected regions, but not actionable for most builders in this room.