StreamRAT Abuses Android Accessibility, MediaProjection and HVNC for Full Device Takeover
ID: 647033e8-33bf-5141-863c-d5d04634241d
STIX ID: report--647033e8-33bf-5141-863c-d5d04634241d
Feed Name: GBHackers
ThreatFabric researchers identified StreamRAT, an Android banking trojan distributed via fake IPTV/sports-streaming ads on Meta and TikTok that exposed ~570,000 Meta users in June–July 2026; the campaign uses a staged dropper, sideloading prompts, default-launcher persistence, a fake VPN to disrupt network checks, Accessibility abuse, MediaProjection and HVNC screen-capture, and a WebSocket C2. The backend and feature set indicate a Malware-as-a-Service model with active C2s and provided IoCs (SHA-256 hashes, package names, IPs). Defenders should treat apps requesting sideloading, Accessibility, VPN changes, and unexpected screen-capture as high risk and apply enterprise mobility restrictions and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
