← Home
CYBERSECURITY

Meta Ads Fuel New Android Trojan Granting Near-Total Device Control

September 9, 2026 Hannah Osei

Deceptive Streaming Campaigns Target Spanish-Speaking Audiences

Cybersecurity firm ThreatFabric revealed that a sophisticated Android banking trojan named StreamRat is actively spreading through targeted advertising on Meta platforms. The malware primarily targets Spanish-speaking users who encounter deceptive television-streaming campaigns. Researchers confirmed that once installed, the software grants attackers almost complete authority over the victim’s mobile device. This discovery highlights a growing trend where social media giants serve as primary vectors for mobile malware distribution.

The attack vector relies heavily on malvertising, or malicious advertising, which has become a preferred method for threat actors seeking high-volume infection rates. By leveraging Meta’s extensive reach, the campaign ensures that the trojan reaches a broad audience quickly. The initial payload is disguised as a popular streaming service, enticing users to download what appears to be a legitimate application. This social engineering approach exploits user trust in well-known brands and services.

Once active, StreamRat establishes a persistent connection with command-and-control servers operated by the threat group. The malware collects sensitive data, including banking credentials, SMS messages, and device information. It can also execute remote commands, allowing attackers to manipulate the device without the user’s knowledge. This level of access transforms a standard smartphone into a powerful tool for financial theft and identity fraud.

How Does StreamRat Achieve Such Extensive Control?

The technical architecture of StreamRat allows it to hook into core system functions, bypassing many standard security checks. It employs rootless techniques to maintain persistence even after reboots, making removal difficult for average users. The trojan can inject code into other applications, particularly banking apps, to intercept transactions and login details. Additionally, it can display overlay windows to capture passwords entered on secure screens.

Researchers observed that the malware uses encrypted communication channels to hide its activity from network monitoring tools. This stealthiness helps it evade detection by traditional antivirus solutions. The use of Meta ads indicates that threat actors are investing significant resources in digital marketing strategies to maximize their return on investment. They carefully select ad placements and creative assets to ensure high click-through rates among vulnerable populations.

Frequently Asked Questions

Who is most at risk from this new Android trojan? Spanish-speaking Android users are the primary target due to the specific focus of the current advertising campaign. However, any user who installs an app from an unverified source or grants excessive permissions remains susceptible to similar attacks.

Can removing the app fully eliminate the threat? Simply uninstalling the application may not remove all components of the trojan. Users should perform a full device scan with reputable security software and review app permissions to ensure no residual code remains active.

How do Meta ads contribute to the spread of malware? Ads serve as the initial entry point, directing users to malicious landing pages. While Meta reviews ads, sophisticated campaigns can slip through by mimicking legitimate services, relying on user interaction to trigger the download process.

Read full article on Tech Site News →