A Fake Streaming App Turned Android Phones Into Remote-Controlled Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A free television offer led Android users to a dangerous download. Ads for a streaming service urged them to install an app that could give criminals control of their phones, rather than access to shows. The malware behind the campaign is called StreamRat.

The ads targeted Spanish-speaking users in Spain. One campaign reached about 570,000 Meta users between June 11 and July 3, 2026.

That measures ad reach, not infections. The lure echoes fake streaming apps spreading TrickMo in another Android banking malware campaign. Analysts at Zimperium noted the campaign’s use of social media ads and a staged installation process.

Zimperium said in a report shared with Cyber Security News (CSN) that StreamRat can capture passwords, watch screens and let an operator control infected devices remotely.

The danger extends beyond stolen logins. An attacker controlling a phone may reach banking apps, messages and other sensitive accounts. The offer appeared to promise entertainment, but the goal was access to personal information and financial accounts.

Researchers have not published a confirmed number of infected devices or successful attacks, so the ad campaign’s large audience should not be mistaken for a victim count.

A Fake Streaming App

The operation starts with ads promoting a free TV service on social platforms. The linked website checks whether a visitor uses Android and hides the download option for other devices.

It then shows instructions tailored to the browser or social app the visitor used to open the page. Those instructions push users to allow installation from outside the usual app store and to enable Accessibility, a feature intended to help people use their phones.

Similar permission abuse underpins Android banking trojans using overlays, which can place convincing login pages above genuine apps.

The first malicious app, a dropper, tries to become the phone’s default home screen. Pressing the Home button then takes the user back to its instructions. It downloads and installs the main trojan before relinquishing that role.

Once the victim grants Accessibility access, StreamRat can observe what appears on screen, record typed information and perform taps or swipes.

It also lists installed apps and reports which one is open. That helps an operator decide when to show a fake banking login or request more data.

The malware offers two ways to view the screen. One uses Android’s regular screen-sharing permission, while the other repeatedly captures screenshots through Accessibility without a sharing indicator. Either view can support remote actions, letting an attacker operate the phone remotely.

Hidden screens and broken connections

StreamRat can cover the display with a black screen or a false system update while an operator continues working behind it. Its fake login pages can collect details entered by the victim. Together, these tools raise the risk of unauthorized account activity.

Before the final malware is installed, the dropper can also request VPN access and create a connection that does not carry normal traffic. Other apps temporarily lose internet access, while the dropper can still download its payload.

Researchers think this may interfere with cloud-based security checks, not disable every protection. A loss of connectivity during installation is worth investigating.

The lure mixes ordinary setup instructions with requests for powerful permissions. Other Android malware sold for remote control has likewise used fake streaming offers to bring users to harmful downloads.

Researchers found a control panel with separate user roles and malware-building tools, suggesting multiple operators could use it. The campaign’s delivery method can change, but the critical turning point remains the same: a user installs an untrusted app and grants it access to the phone.

Users should avoid app downloads offered through social ads or unfamiliar websites, and question any streaming app that requests Accessibility, screen capture or VPN access.

Organizations should review phones showing unexpected permission changes, default home-screen changes or installation from outside approved sources. For context, banking malware using fake download pages presents a similar warning about deceptive app installs.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c StreamRat-related Android app sample.
Package name io.base.one887 Package associated with the streaming-app sample.
Application name StrεαmTV Pro Name used by the streaming-app sample.
SHA-256 ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3 StreamRat-related Android app sample.
Package name io.meat.hint Package associated with the second sample.
Application name Sistema de vídeo Name used by the second sample.
C2 IP address 45.147.28[.]59 Command-and-control infrastructure.
C2 IP address 193.32.2[.]245 Command-and-control infrastructure.
File name r1edmi.html Page used to tailor installation instructions.
File name app.apk Download name assigned to the dropper.
File name set_launcher.html Dropper page used during home-screen setup.
File name index.html Dropper page that triggers the payload download.
File name vpn_required.html Page included in the dropper’s installation flow.
File name pattern update_{timestamp}.apk Payload saved in the Downloads folder.
File name pattern <package_name>.html Temporary file used for an app-specific overlay.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post A Fake Streaming App Turned Android Phones Into Remote-Controlled Devices appeared first on Cyber Security News.