StreamRat Spreads Through Fake Android Streaming Ads

Published September 7, 2026

Attackers are promoting a fake television-streaming service to persuade Android users to install StreamRat. The malware can monitor the screen, capture typed information and show fake login pages.

Report priority
High
Involves
Android

What is known

  • Attackers place Meta and TikTok ads for a free service called Steamtv Esp.
  • On Android devices, the linked site offers app.apk and explains how to allow installation from outside Google Play.
  • The victim must install and launch the downloaded app.
  • It asks to become the default Home app and to create a VPN that temporarily blocks other apps' internet access while it downloads and installs the main malware.
  • If the victim grants Accessibility access, StreamRat can monitor and control on-screen activity, capture typed data and display fake login pages that steal credentials.

What to do

First, determine whether you downloaded and opened app.apk from a Steamtv Esp advertisement or its linked site. In Android Settings, review installed apps, Accessibility access, VPN configurations and the default Home app for unfamiliar entries added around that time. These permissions are risk signals, not proof of StreamRat or compromise. The source doesn't provide a package name, file hash or reliable test that can rule out infection.

Don't install the advertised APK, and deny unexpected Accessibility, VPN or default Home requests. If you installed and launched it, give your IT or mobile-device administrator the advertisement or site address, installation time and permissions granted, then ask them to inspect the device and remove any related app and payload. SecurityOnline's report provides the campaign details. Removing the initial app alone does not confirm that the downloaded malware is gone.

Reported details

Between June 11 and July 3, 2026, one StreamRat ad campaign impersonating the free streaming app "Steamtv Esp" reached about 570,000 Meta accounts before victims were funneled to the malicious app.apk download.

SecurityOnline, citing ThreatFabric, says StreamRat communicates with its control server over a WebSocket connection and sends a device identifier, model and Android API level. It can stream screenshots, send a structured JSON description of on-screen interface elements, capture typed data and display fake login pages inside the app. The initial installer reportedly resembles Mirax and downloads malware through a GitHub account previously used to distribute Mirax. Researchers suspect the malware is offered as a service to other attackers and associate the operator with earlier GodFather malware use.