Fake streaming ads on Meta and TikTok hijack Android phones

Published

The advert offered free TV streaming. It ran on Meta from June 11 to July 3, 2026 under the campaign name Steamtv Esp., and it put itself in front of roughly 570,000 people. The same banners were reused on TikTok. Tap one on an Android phone and the site did not just hand over a file, it coached the visitor through switching off the setting that stops Android installing apps from outside the Play Store.

What arrived at the end of that process was StreamRat, an Android banking trojan that gives its operators, in the words of the researchers who documented it, near complete control over the infected device.

The site decided what you saw before it offered anything

ThreatFabric, which named and analysed the malware, found the landing page ran two checks on each visitor. First it tested whether the visitor was on Android at all, and refused the download to everyone else, concentrating the effort on devices the malware can actually infect. Then it worked out whether the arrival came from Instagram, TikTok, Facebook or an ordinary browser, and served installation instructions tailored to that path.

That is the detail worth sitting with. This was not a generic malicious download page. It was written to walk a curious person past the exact security warnings designed to stop them.

The install itself runs in two stages. The phishing site delivers a dropper hosted in a GitHub repository, and the dropper then fetches StreamRat. ThreatFabric reports the dropper implements an internet-blocking mechanism using a fake VPN connection, which cuts the phone off at a convenient moment. Two package names appear in the campaign: io.base.one887, presenting itself as a streaming app, and io.meat.hint, posing as a Spanish-language system video component.

What it does once it is on the phone

StreamRat is a banking trojan and infostealer, sold to operators as a service with distinct user, supervisor and admin roles. ThreatFabric documents remote control through VNC and hidden-screen operation built on Android's MediaProjection and Accessibility Services, collection of the on-screen interface tree, keylogging, and credential-stealing overlays: fake login screens that sit on top of a real banking app and capture what is typed.

It can also block the internet, blank the screen, and lock or unlock the device using PINs and patterns it has intercepted. A black page or a fake Android update screen keeps the victim looking at something harmless while the operator works behind it. ThreatFabric notes the same threat actor previously distributed the GodFather and Mirax trojans.

Reach is not the same as infections

The 570,000 figure describes how many Meta users the adverts reached. It is not a count of downloads and not a count of infections, and nobody has published either. What it does measure is how quickly paid social advertising can put a lure in front of a very large audience, in feeds where people expect to see promotions and have no reason to be suspicious of one. The campaign was aimed at Spanish speakers, with most observed victims in Spain.

Accessibility access is the moment to stop

Install Android apps through Google Play wherever possible, and treat an app advertised in a social feed with the same suspicion as a link in an unexpected text message. The decisive moment is the permission prompt: an app asking for Accessibility access, screen-sharing, Device Admin rights or permission to become the default launcher is asking for the capabilities StreamRat needs, and a streaming player has no use for any of them.

Malwarebytes, which also flagged the campaign, detects the payload as Android/PUP.Agent.ACR02DB0614H7 and advises that anyone who installed a suspicious APK and granted it Accessibility access should disconnect the phone from Wi-Fi and mobile data, revoke that access and remove the app if possible, then change passwords and contact their bank from a different device. A factory reset may be the only reliable option.

ThreatFabric lists two command and control servers for the campaign: 45[.]147[.]28[.]59 and 193[.]32[.]2[.]245.

The delivery is what has changed here, not the malware. Android trojans have been running fraud from the victim's own handset for a while, as our coverage of ToxicPanda set out. Buying the traffic from Meta and TikTok simply removes the hard part, which was ever getting anyone to look.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions