Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical VMware Workstation and Fusion Flaws Let Attackers Execute Code
September 3, 2026
Critical Node.js Vulnerability CVE-2024-2798 Lets Attackers Deploy Malware
September 3, 2026
StreamRAT Android Trojan Grants Full Remote Control via VNC, Accessibility
September 3, 2026
Home/Threats/StreamRAT Android Trojan Grants Full Remote Control via VNC, Accessibility
Threats

StreamRAT Android Trojan Grants Full Remote Control via VNC, Accessibility

Key Takeaways A new Android banking trojan, StreamRAT, offers attackers extensive remote control over infected devices. The malware leverages VNC and Android Accessibility Services to view screens,...

Sarah simpson
Sarah simpson
September 3, 2026 4 Min Read
3 0

Key Takeaways

  • A new Android banking trojan, StreamRAT, offers attackers extensive remote control over infected devices.
  • The malware leverages VNC and Android Accessibility Services to view screens, perform actions, and deploy credential-stealing overlays.
  • Campaigns primarily target Spanish-speaking Android users through deceptive ads on Meta platforms and TikTok, posing as free streaming services.
  • StreamRAT employs a multi-stage infection process, including a dropper that can disrupt internet access to hinder analysis.
  • Users are advised to avoid unofficial app downloads, scrutinize permission requests, and promptly remove suspicious applications.

A sophisticated new Android banking trojan, dubbed StreamRAT, has emerged, providing threat actors with comprehensive remote control capabilities over compromised mobile devices. This malware combines real-time screen viewing, remote interaction, and convincing login window overlays, transforming a simple app download into a potential complete account takeover.

Table Of Content

  • Key Takeaways
  • StreamRAT Uses VNC and Accessibility for Device Control
  • Delivery Chain and Evasion Risks
  • What You Should Do

Early campaigns associated with StreamRAT have specifically targeted Spanish-speaking Android users. Attackers utilized advertisements on Meta platforms and TikTok to distribute the malware. One notable advertising push, tracked between June 11 and July 3, 2026, reached approximately 570,000 Meta users, predominantly in Spain. Security researchers identified StreamRAT while monitoring the “Steamtv Esp” campaign, which used streaming service themes as a lure.

The operation funnels victims through phishing websites and a multi-stage installation process, bypassing official app stores to install malicious Android packages. Threat Fabric said in a report that the distribution chain frequently leveraged a GitHub repository previously linked to Mirax distribution, indicating that the operators are reusing established delivery infrastructure while adapting their final malicious payloads.

StreamRAT’s significance lies in its fusion of traditional banking fraud functionalities with advanced remote control tools, enabling attackers to monitor and manipulate devices in real time. Furthermore, the malware’s control panel exhibits characteristics consistent with a malware-as-a-service (MaaS) model, suggesting that it could be licensed or offered to other malicious actors for their own campaigns.

StreamRAT Uses VNC and Accessibility for Device Control

Upon successful installation, StreamRAT initiates a request for the victim to activate Android Accessibility Services. While a legitimate feature designed to assist users with disabilities, this permission, when exploited, grants attackers the ability to read screen content and execute various actions such as taps, swipes, navigation, and notification management. This abuse of Accessibility Services is a common tactic observed in other Android banking malware campaigns.

The trojan incorporates two distinct screen viewing mechanisms. The first, a standard VNC option, utilizes Android’s native screen-capture system. The second, a “hidden VNC” mode, repeatedly captures screenshots via Accessibility Services without displaying a visible screen-sharing indicator to the user. Both methods provide attackers with a visual feed of the device and enable remote interaction.

Beyond screen viewing, StreamRAT can reconstruct the device’s interface as structured text, capture keystrokes, enumerate installed applications, and display convincing overlay screens designed to steal credentials. To further facilitate covert operations, the malware can present a black screen or a fake update display, effectively blocking the victim’s touch input while the attacker continues to operate in the background. This technique is a known pattern associated with the misuse of Android Accessibility features.

The cumulative effect of these capabilities extends beyond mere surveillance. An attacker can monitor which applications a victim opens, subsequently deliver a tailored fake login page, harvest entered credentials, and utilize intercepted unlock information to gain full access to the device. This comprehensive control places sensitive assets, including banking sessions, private messages, and other personal accounts, at severe risk.

Delivery Chain and Evasion Risks

The infection process typically commences with social media advertisements promoting a fictitious free television-streaming service. The malicious landing page first verifies if the visitor is using an Android device, then tailors its instructions to guide the user through enabling “unknown sources” installation and granting Accessibility permissions. This social engineering relies on urgency and familiarity rather than exploiting software vulnerabilities.

A first-stage dropper attempts to set itself as the default home application, ensuring the victim remains within its malicious interface even when pressing the home button. Following this, it retrieves and installs the final StreamRAT payload. This deceptive tactic mirrors similar techniques observed in other phone-based banking fraud schemes.

Before downloading the main malware, the dropper can establish a deliberately faulty VPN connection. This connection disrupts general internet access for the device while selectively excluding itself, potentially hindering online reputation checks or cloud-based analysis. While this may impede certain forms of detection, researchers note it does not completely negate offline protection measures.

StreamRAT communicates with its command and control (C2) server using WebSocket connections, efficiently conserving bandwidth by avoiding the transmission of redundant screen and interface data. This engineering focus on reliable, scalable remote operations through WebSocket technology reflects an evolving trend in sophisticated Android threats.

What You Should Do

  • Avoid Unofficial Downloads: Never download Android Package Kit (APK) files from advertisements, unsolicited messages, or unofficial websites, particularly those offering free streaming services or urgent updates.
  • Scrutinize Permissions: Deny unexpected requests for critical permissions such as Accessibility Services, installation from unknown sources, or VPN access.
  • Remove Suspicious Apps: Promptly uninstall any unfamiliar applications, especially those that combine installation capabilities with VPN permissions.
  • Enable Google Play Protect: Ensure Google Play Protect is active on your Android device to scan for potentially harmful applications.
  • Organizational Monitoring: Organizations should implement mobile device monitoring solutions to flag unusual Accessibility activity, unexpected screen-capture requests, changes to default launcher applications, and installations from outside managed app stores.

Indicators of compromise (IoCs): <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Gentlemen Ransomware Disables EDR, Backups Before Network Encryption

Next Post

Critical Node.js Vulnerability CVE-2024-2798 Lets Attackers Deploy Malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Sangoma Switchvox RCE Vulnerability Actively Exploited
September 3, 2026
Critical WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection
September 3, 2026
Critical Apache HTTP Server Vulnerability Lets Attackers Phish Users
September 3, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us