hacker-news · Crawled Sep 2, 2026

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

7 IoCs
Read original article ↗

AI Summary

A malvertising campaign on Meta platforms targeted Spanish-speaking users with ads promoting a fake TV streaming app that delivers the StreamRat Android banking trojan. The malware, once installed, requests Accessibility and other permissions to enable remote device control, keystroke logging, and overlay attacks. The dropper first installs a non-functional VPN to disrupt analysis, then downloads and installs the final payload. The campaign ran from June 11 to July 3, 2026, and was also promoted via TikTok, though attribution remains unconfirmed.

AI-extracted · verify before operational use

Indicators of Compromise 7 extracted

Type Value Detail
SHA-256 e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c Details →
Package io.base.one887 Details →
Filename app.apk Details →
SHA-256 ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 Details →
Package io.meat.hint Details →
IP 45[.]147[.]28[.]59 Details →
IP 193[.]32[.]2[.]245 Details →