By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Meta Ads Promote StreamRat Android Trojan

Cybersecurity researchers have disclosed the existence of a new Android banking trojan named StreamRat, which was actively promoted to Spanish-speaking users through a deceptive advertising campaign on Meta's platforms. ThreatFabric, a cybersecurity firm, reported that this campaign specifically targeted users in Spain and reached an estimated 570,950 Meta accounts within the European Union. The trojan's primary function is to grant its operators near-complete control over infected devices, posing a significant threat to user data and device security.
The StreamRat trojan is designed to steal sensitive financial information, including banking credentials, and can perform various malicious actions once it infects an Android device. The campaign's advertisements were crafted to appear legitimate, likely mimicking legitimate television streaming service promotions to lure unsuspecting users into downloading the malicious application. This tactic highlights a sophisticated social engineering approach used by threat actors to distribute malware. The broad reach of the campaign, impacting over half a million Meta accounts, underscores the potential scale of this threat.
ThreatFabric's analysis indicates that StreamRat possesses advanced capabilities for remote access and data exfiltration. Once installed, the trojan can intercept communications, log keystrokes, and potentially gain access to other sensitive applications and data stored on the device. The targeting of Spanish-speaking users suggests a specific regional focus for this operation, although the use of Meta's advertising network means the malware could potentially spread beyond this initial demographic if not contained. The firm's findings were published in a detailed report, providing technical insights into the trojan's operation and the methods used in its distribution.
The use of Meta's advertising infrastructure by malicious actors is a recurring concern for cybersecurity professionals. Platforms like Meta, which have vast user bases and sophisticated advertising tools, can be exploited to distribute malware and phishing campaigns at scale. The effectiveness of the StreamRat campaign demonstrates the need for continuous vigilance from both platform providers and end-users to identify and mitigate such threats. The estimated number of affected accounts suggests a significant number of individuals may have been exposed to the risk of infection, emphasizing the critical importance of robust security practices and awareness among mobile device users.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.