hacker-news · Crawled Sep 2, 2026
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
7 IoCs
Read original article ↗
AI Summary
A malvertising campaign on Meta platforms targeted Spanish-speaking users with ads promoting a fake TV streaming app that delivers the StreamRat Android banking trojan. The malware, once installed, requests Accessibility and other permissions to enable remote device control, keystroke logging, and overlay attacks. The dropper first installs a non-functional VPN to disrupt analysis, then downloads and installs the final payload. The campaign ran from June 11 to July 3, 2026, and was also promoted via TikTok, though attribution remains unconfirmed.
AI-extracted · verify before operational use
Indicators of Compromise 7 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c | Details → |
| Package | io.base.one887 | Details → |
| Filename | app.apk | Details → |
| SHA-256 | ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 | Details → |
| Package | io.meat.hint | Details → |
| IP | 45[.]147[.]28[.]59 | Details → |
| IP | 193[.]32[.]2[.]245 | Details → |