StreamRAT Android Trojan Grants Full Remote Control via VNC, Accessibility
Key Takeaways A new Android banking trojan, StreamRAT, offers attackers extensive remote control over infected devices. The malware leverages VNC and Android Accessibility Services to view screens,...
Key Takeaways
- A new Android banking trojan, StreamRAT, offers attackers extensive remote control over infected devices.
- The malware leverages VNC and Android Accessibility Services to view screens, perform actions, and deploy credential-stealing overlays.
- Campaigns primarily target Spanish-speaking Android users through deceptive ads on Meta platforms and TikTok, posing as free streaming services.
- StreamRAT employs a multi-stage infection process, including a dropper that can disrupt internet access to hinder analysis.
- Users are advised to avoid unofficial app downloads, scrutinize permission requests, and promptly remove suspicious applications.
A sophisticated new Android banking trojan, dubbed StreamRAT, has emerged, providing threat actors with comprehensive remote control capabilities over compromised mobile devices. This malware combines real-time screen viewing, remote interaction, and convincing login window overlays, transforming a simple app download into a potential complete account takeover.
Table Of Content
Early campaigns associated with StreamRAT have specifically targeted Spanish-speaking Android users. Attackers utilized advertisements on Meta platforms and TikTok to distribute the malware. One notable advertising push, tracked between June 11 and July 3, 2026, reached approximately 570,000 Meta users, predominantly in Spain. Security researchers identified StreamRAT while monitoring the “Steamtv Esp” campaign, which used streaming service themes as a lure.
The operation funnels victims through phishing websites and a multi-stage installation process, bypassing official app stores to install malicious Android packages. Threat Fabric said in a report that the distribution chain frequently leveraged a GitHub repository previously linked to Mirax distribution, indicating that the operators are reusing established delivery infrastructure while adapting their final malicious payloads.
StreamRAT’s significance lies in its fusion of traditional banking fraud functionalities with advanced remote control tools, enabling attackers to monitor and manipulate devices in real time. Furthermore, the malware’s control panel exhibits characteristics consistent with a malware-as-a-service (MaaS) model, suggesting that it could be licensed or offered to other malicious actors for their own campaigns.
StreamRAT Uses VNC and Accessibility for Device Control
Upon successful installation, StreamRAT initiates a request for the victim to activate Android Accessibility Services. While a legitimate feature designed to assist users with disabilities, this permission, when exploited, grants attackers the ability to read screen content and execute various actions such as taps, swipes, navigation, and notification management. This abuse of Accessibility Services is a common tactic observed in other Android banking malware campaigns.
The trojan incorporates two distinct screen viewing mechanisms. The first, a standard VNC option, utilizes Android’s native screen-capture system. The second, a “hidden VNC” mode, repeatedly captures screenshots via Accessibility Services without displaying a visible screen-sharing indicator to the user. Both methods provide attackers with a visual feed of the device and enable remote interaction.
Beyond screen viewing, StreamRAT can reconstruct the device’s interface as structured text, capture keystrokes, enumerate installed applications, and display convincing overlay screens designed to steal credentials. To further facilitate covert operations, the malware can present a black screen or a fake update display, effectively blocking the victim’s touch input while the attacker continues to operate in the background. This technique is a known pattern associated with the misuse of Android Accessibility features.
The cumulative effect of these capabilities extends beyond mere surveillance. An attacker can monitor which applications a victim opens, subsequently deliver a tailored fake login page, harvest entered credentials, and utilize intercepted unlock information to gain full access to the device. This comprehensive control places sensitive assets, including banking sessions, private messages, and other personal accounts, at severe risk.
Delivery Chain and Evasion Risks
The infection process typically commences with social media advertisements promoting a fictitious free television-streaming service. The malicious landing page first verifies if the visitor is using an Android device, then tailors its instructions to guide the user through enabling “unknown sources” installation and granting Accessibility permissions. This social engineering relies on urgency and familiarity rather than exploiting software vulnerabilities.
A first-stage dropper attempts to set itself as the default home application, ensuring the victim remains within its malicious interface even when pressing the home button. Following this, it retrieves and installs the final StreamRAT payload. This deceptive tactic mirrors similar techniques observed in other phone-based banking fraud schemes.
Before downloading the main malware, the dropper can establish a deliberately faulty VPN connection. This connection disrupts general internet access for the device while selectively excluding itself, potentially hindering online reputation checks or cloud-based analysis. While this may impede certain forms of detection, researchers note it does not completely negate offline protection measures.
StreamRAT communicates with its command and control (C2) server using WebSocket connections, efficiently conserving bandwidth by avoiding the transmission of redundant screen and interface data. This engineering focus on reliable, scalable remote operations through WebSocket technology reflects an evolving trend in sophisticated Android threats.
What You Should Do
- Avoid Unofficial Downloads: Never download Android Package Kit (APK) files from advertisements, unsolicited messages, or unofficial websites, particularly those offering free streaming services or urgent updates.
- Scrutinize Permissions: Deny unexpected requests for critical permissions such as Accessibility Services, installation from unknown sources, or VPN access.
- Remove Suspicious Apps: Promptly uninstall any unfamiliar applications, especially those that combine installation capabilities with VPN permissions.
- Enable Google Play Protect: Ensure Google Play Protect is active on your Android device to scan for potentially harmful applications.
- Organizational Monitoring: Organizations should implement mobile device monitoring solutions to flag unusual Accessibility activity, unexpected screen-capture requests, changes to default launcher applications, and installations from outside managed app stores.
Indicators of compromise (IoCs): <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-f0510061/b9ed3539-fd50-4782-8804-
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.