This Free Android Streaming App Is Actually Malware That Screenshots Your Phone 5 Times a Second

StreamRat malware can remotely control your Android phone, capture screens five times a second, and steal your credentials and other sensitive data.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

You see an ad for a website offering free streaming services, and your eyes light up instantly. This one website could save you hundreds of dollars in subscription fees while still giving you access to the most premium and latest content. Only, the website isn’t what it looks like.

Researchers have found a new malware called StreamRat that promises free streaming but can infect your Android device and steal sensitive information from it.[1] It can also capture a screenshot of your device around five times a second, allowing attackers to see what’s happening on your screen and remotely control your device.

They could open apps, type in your login IDs and passwords, and even draw your PIN patterns, potentially carrying out financial fraud, identity theft, and targeted phishing attacks.

Here’s everything you should know about this new streaming scam and how to protect your Android device from malware.

In this article
How StreamRat infects your Android device
How StreamRat can spy on and control your phone
What can you do to protect yourself
The bottom line

How StreamRat infects your Android device

The attackers first set up a website and ran ads on the Meta platform and TikTok, advertising a free TV streaming service. As researchers found, one ad campaign reached about 570,000 Meta users between June 11 and July 3, 2026.

When someone clicks on the ad, the website first uses JavaScript to check whether the potential victim is using an Android device. If Android is not detected, the user doesn’t see the download button at all.

Once Android users click on the download button, the site redirects to a second page (r1edmi.html). This page shows step-by-step installation instructions, usually requiring the victim to allow downloads from unknown sources and grant Accessibility Service permissions.

The Accessibility settings within Android allow people with disabilities to use their devices, but it’s exactly what the malware needs to take control of the device later. This is the similar to how the RatHat malware works, another Android malware that can steal your banking passwords by tracking your fingers.

The r1edmi.html page also downloads a file called app.apk. This isn’t StreamRat itself, but a dropper whose job is to prepare your Android device for installing StreamRat.

  • It first asks to be set as the phone’s default home launcher, so that whenever you press the Home button on your device, you are redirected to this dropper, making it difficult to escape the loop.
  • It then asks for VPN permission and creates a fake VPN connection that routes your traffic to a dead end. This cuts off the internet for other apps, potentially preventing security products from performing cloud-based checks on the malware.
  • Then it downloads the StreamRat payload and requests permission to install the app. Once the payload is launched, the dropper turns off the fake VPN and removes itself as the default launcher.

From here on, StreamRat takes over.

How StreamRat can spy on and control your phone

As per the published report, once your device has been infected with StreamRat, attackers could gain near-complete control of your device remotely.

Spying and data theft

As soon as StreamRat connects to the attacker's server, it starts sending data from the victim's device, starting with an extensive list of installed apps. This allows attackers to identify which apps are being used on the device.

StreamRat can also log what the victim types and keep track of which app is in the foreground. Every time the victim switches to a different app, the malware can report the app package name to the server, so the attacker knows which app the victim is using.

StreamRat can also capture screen lock patterns or PINs, potentially allowing the attacker to get into the victim’s phone even when it’s locked.

Screen viewing

This is perhaps the most dangerous consequence of StreamRat. The malware uses three different ways to see what’s going on on the victim’s screen.

  • The first is VNC mode, which uses Android’s built-in screen-sharing feature called MediaProjection. StreamRat can interact with the screen-sharing permission dialog and select full-screen capture. However, Android usually shows a screen-sharing indicator in the status bar, which can alert you.
  • This is why there’s a second, hidden VNC mode, which takes a screenshot of your screen every 200 milliseconds. There’s nothing visible that could directly alert you that someone is watching your screen every one-fifth of a second.
  • A third method called the Accessibility Node Viewer could allow StreamRat to read the structure of everything displayed on the screen, package it as structured data, and send it to the attacker’s server. This is a fast and lightweight way to collect information displayed on the device, including text.

Remote control

An attacker could use a victim’s phone as if it were their own. They can tap anywhere on the screen, swipe between two points, and interact with the device remotely through Accessibility Services.

Attackers may also type by pasting text into a field, giving them another way to interact with apps on the victim’s device. This could potentially allow them to enter sensitive information or perform actions inside banking and other apps.

Phishing overlays

StreamRat attackers could also use fake screens placed on top of real apps, called overlays, to trick the victim into giving away their credentials. For instance, when you open your banking app, StreamRat can show you a fake overlay mimicking your banking app’s interface.

You may enter your user ID, password, and two-factor authentication details on the screen, trusting it to be the legitimate app. The fake overlay can pass whatever information the victim enters back to the malware, hiding the attack from the victim, much like a phishing page.

Hiding the attack from victims

All of this can happen without the victim immediately noticing anything wrong. StreamRat could hide the attack by using cover screens controlled from the attacker panel’s maintenance section. This black overlay could cover about 98% of the screen and block the victim’s touches. What the victim sees is essentially a black or fake update screen, while the attacker can continue to control the device remotely.

What can you do to protect yourself

There are several things you can do to protect your Android device from StreamRat.

  1. Never download apps from unknown sources: Make sure you only download apps from the official Google Play Store or other trusted sources, and not from unverified third-party sources.
  2. Beware of the permissions you grant to apps: A streaming app shouldn’t require Accessibility access or open a new VPN connection. These are red flags that you shouldn’t ignore. Also, check the permissions you have granted to other apps from time to time and revoke any additional access that’s not required for an app’s functioning.
  3. Keep Google Play Protect switched on: Play Protect is enabled by default on Play Protect-certified Android devices and checks apps installed from unknown sources. Although StreamRat’s internet-blocking trick is designed to interfere with cloud-based security checks, it doesn’t completely disable Play Protect, which can still detect some known harmful apps offline.
  4. Use a third-party antivirus program: A good antivirus solution can provide an additional layer of protection against StreamRat by detecting malicious apps or suspicious files before they are installed on your device. It can also help flag malicious websites and downloads that could lead to the malware.

If you believe that your phone has already been infected by StreamRat, immediately cut off the attacker’s access by turning on airplane mode, which can help stop the malware from communicating with the attacker’s server.

Then go to Settings and Accessibility and switch off any services that you don’t recognize, and then uninstall the suspicious app, including both the streaming app and anything that appeared after it.

After this, change all your banking passwords. Make sure you set a strong, unique password each time, as well as changing your email and social media passwords and setting a new phone PIN or pattern. You can both change and store your passwords easily using a password manager.

A factory reset may also be worth considering if you want to thoroughly clean your device of malware. You could also consider an identity theft protection service that scans known data breach databases and the dark web for your information and alerts you if it finds it.

The bottom line

StreamRat advertises free streaming services, but once inside your system, it could allow attackers to use your phone as if it were their own. They can steal login details, read text on your screen, capture banking credentials, hijack login sessions, and even capture your phone’s PIN or pattern.

That said, you can largely avoid this type of malware attack with good cyber hygiene. Do not fall for the promise of free streaming and download apps from third-party sources, and pay close attention to the kind of permissions a newly installed app asks for. A streaming app shouldn’t need Accessibility access or a VPN connection.

Protect Every Aspect of Your Digital Life — Even Your Time
4.7
Editorial Rating
Claim Deal
On TotalAV's website
2026 Editors’ Choice
Best Antivirus for Safe Browsing
Antivirus Software
TotalAV
PROMOTION: Get $80 Off
  • An antivirus that scores 18/18 on AV-TEST for Windows and macOS, with top marks across all test categories
  • Passed every malware and drive-by download test we ran, quarantining threats automatically
  • Includes a junk cleaner, app uninstaller, and browser cleaner to keep your device running smoothly alongside the antivirus

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Uncovering StreamRat: From Meta Ads to Full Device Takeover