Actor Profile

ThreatFabric is the cybersecurity research firm that discovered and analyzed the StreamRat campaign. The actual threat actor behind StreamRat remains unattributed. ThreatFabric assessed that StreamRat was developed by individuals with prior experience in the Android malware ecosystem, noting technical sophistication and operational links to an earlier Mirax campaign through shared GitHub infrastructure and similar dropper code. The actor's motivation appears to be financial gain through banking credential theft and device takeover targeting Spanish-speaking users, primarily in Spain and the broader European Union.

TTPs (Tactics, Techniques, Procedures)

The campaign leverages malvertising on Meta platforms (T1583.008 Malvertising) to distribute StreamRat via fake television-streaming lures. Initial access occurs through social engineering (T1204.002 Malicious File) as victims sideload a dropper APK. The dropper requests Home application privileges and establishes a VPN connection (T1090 Proxy) to block network traffic during payload installation, potentially evading detection. The dropper downloads the StreamRat payload to the Downloads directory and installs it via Android's package mechanism. StreamRat requests Accessibility Service permissions (T1629.001 Abuse Accessibility Features) to enable keylogging (T1056.001 Keylogging), credential harvesting via overlay attacks (T1417 Input Capture), screen capture using MediaProjection API and takeScreenshot() methods (T1513 Screen Capture), and remote device control. Command-and-control communication (T1071 Application Layer Protocol) is established after Accessibility permissions are granted. The malware provides operators near-complete device control for financial fraud operations.

Targets & Patterns

StreamRat specifically targets Spanish-speaking Android users in the financial services and social media sectors. The campaign focused geographically on Spain with broader reach across the European Union, where approximately 570,950 Meta accounts viewed the malicious advertisements at least once between June 11 and July 3, 2026. The targeting pattern suggests the actor seeks banking credentials and financial data from Spanish-speaking populations, leveraging culturally relevant lures (fake Spanish television streaming apps named "StrεαmTV Pro" and "Sistema de vídeo"). The choice of Meta platforms (Facebook, Instagram) and potentially TikTok as distribution vectors indicates targeting of users who engage with social media advertising, particularly those interested in streaming entertainment content.

Historical Context

ThreatFabric linked StreamRat infrastructure to an earlier Mirax banking trojan campaign. The StreamRat payload was hosted on a GitHub account previously associated with Mirax operations, and the dropper code closely resembled the Mirax dropper. According to Cleafy's Mirax analysis, that campaign also used GitHub releases to host droppers with backup links and daily package updates. This operational continuity suggests StreamRat represents an evolution or continuation of the Mirax threat actor's activities, with the same development team or closely related operators refining their Android banking trojan capabilities and distribution methods.

Defensive Recommendations

  • Monitor for Android applications requesting unusual permission combinations, particularly streaming apps requesting Accessibility Service, VPN establishment, Home application privileges, and installation from unknown sources (T1629.001)
  • Implement user awareness training emphasizing that legitimate streaming applications do not require Accessibility permissions or system-level controls; advise users to abort installations when encountering such requests
  • Deploy mobile threat defense solutions capable of detecting sideloaded APKs with suspicious permission requests and known IoCs: SHA-256 hashes e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c and ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3
  • Block network communication to identified C2 infrastructure: IP addresses 45.147.28[.]59 and 193.32.2[.]245 at perimeter and mobile device management layers
  • Monitor for applications abusing Android MediaProjection API and Accessibility takeScreenshot() methods for unauthorized screen capture (T1513); correlate with unexpected VPN establishment during app installation phases

---

# Geopolitical Context

Geopolitical Context

The StreamRat campaign represents a sophisticated financially motivated operation leveraging major social media platforms to distribute banking malware within the European Union. The targeting of Spanish-speaking populations through Meta's advertising infrastructure—reaching approximately 570,950 EU accounts—demonstrates how threat actors exploit legitimate digital advertising ecosystems to circumvent traditional distribution barriers. The campaign's focus on Spain, a major EU economy, and its use of social engineering techniques disguised as television streaming services reflects an understanding of regional consumer behavior and digital entertainment consumption patterns. The operation's technical sophistication, including multi-stage dropper mechanisms and VPN-based traffic manipulation, suggests development by actors with prior Android malware experience, though ThreatFabric provided no state-actor attribution. The campaign's infrastructure links to an earlier operation (Mirax) indicate potential continuity in tooling and methodology within the cybercriminal ecosystem.

State Actor Alignment

ThreatFabric did not attribute the StreamRat campaign to any named threat actor or state-sponsored group. The operation appears consistent with financially motivated cybercrime rather than state-directed espionage or influence operations. The use of GitHub for payload hosting and the focus on banking credential theft through overlay attacks and device control suggest a profit-driven criminal enterprise. No sanctions implications or state policy connections were identified in the available reporting. The campaign's targeting methodology—leveraging commercial advertising platforms rather than strategic infrastructure compromise—further supports a criminal rather than geopolitical motivation.

Business Impacty pro region

The campaign's primary impact centers on the European Union, specifically targeting Spain's digital consumer base through Spanish-language lures. The reach of 570,950 Meta accounts across the EU demonstrates significant exposure, though actual infection rates remain unreported. The operation highlights vulnerabilities in the EU's digital advertising ecosystem and raises questions about platform responsibility for malicious advertisement vetting, particularly relevant given ongoing EU regulatory efforts around digital services and platform accountability under frameworks like the Digital Services Act. The campaign's June-July 2026 timeframe and subsequent disclosure in September reflects detection and response coordination within the European cybersecurity community. The financial services sector across Spain and potentially other Spanish-speaking EU regions faces elevated risk from credential theft and account takeover. The incident may inform ongoing EU policy discussions regarding mobile security standards, advertising platform obligations, and cross-border cybercrime enforcement cooperation.

Forecast

If similar campaigns continue to exploit major social media advertising platforms, EU regulators may intensify scrutiny of Meta and other platforms' advertisement vetting processes, potentially leading to enhanced compliance requirements under existing digital services legislation. Should infection rates prove substantial, Spanish financial institutions are likely to implement additional fraud detection measures and customer notification protocols. If the threat actors behind StreamRat maintain operational continuity—as suggested by infrastructure links to the earlier Mirax campaign—further iterations targeting other EU language groups or regions may emerge in the coming months. Increased collaboration between platform providers, cybersecurity vendors, and EU law enforcement agencies is probable if the campaign's financial impact reaches thresholds warranting coordinated investigation. Mobile security vendors are likely to update detection signatures based on the published indicators of compromise, potentially reducing the effectiveness of current StreamRat variants while driving threat actor adaptation.