All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
You see an ad for a website offering free streaming services, and your eyes light up instantly. This one website could save you hundreds of dollars in subscription fees while still giving you access to the most premium and latest content. Only, the website isn’t what it looks like.
Researchers have found a new malware called StreamRat that promises free streaming but can infect your Android device and steal sensitive information from it.[1] It can also capture a screenshot of your device around five times a second, allowing attackers to see what’s happening on your screen and remotely control your device.
They could open apps, type in your login IDs and passwords, and even draw your PIN patterns, potentially carrying out financial fraud, identity theft, and targeted phishing attacks.
Here’s everything you should know about this new streaming scam and how to protect your Android device from malware.
How StreamRat can spy on and control your phone
What can you do to protect yourself
The bottom line
How StreamRat infects your Android device
The attackers first set up a website and ran ads on the Meta platform and TikTok, advertising a free TV streaming service. As researchers found, one ad campaign reached about 570,000 Meta users between June 11 and July 3, 2026.
When someone clicks on the ad, the website first uses JavaScript to check whether the potential victim is using an Android device. If Android is not detected, the user doesn’t see the download button at all.
Once Android users click on the download button, the site redirects to a second page (r1edmi.html). This page shows step-by-step installation instructions, usually requiring the victim to allow downloads from unknown sources and grant Accessibility Service permissions.
The Accessibility settings within Android allow people with disabilities to use their devices, but it’s exactly what the malware needs to take control of the device later. This is the similar to how the RatHat malware works, another Android malware that can steal your banking passwords by tracking your fingers.
The r1edmi.html page also downloads a file called app.apk. This isn’t StreamRat itself, but a dropper whose job is to prepare your Android device for installing StreamRat.
- It first asks to be set as the phone’s default home launcher, so that whenever you press the Home button on your device, you are redirected to this dropper, making it difficult to escape the loop.
- It then asks for VPN permission and creates a fake VPN connection that routes your traffic to a dead end. This cuts off the internet for other apps, potentially preventing security products from performing cloud-based checks on the malware.
- Then it downloads the StreamRat payload and requests permission to install the app. Once the payload is launched, the dropper turns off the fake VPN and removes itself as the default launcher.
From here on, StreamRat takes over.
How StreamRat can spy on and control your phone
As per the published report, once your device has been infected with StreamRat, attackers could gain near-complete control of your device remotely.
Spying and data theft
As soon as StreamRat connects to the attacker's server, it starts sending data from the victim's device, starting with an extensive list of installed apps. This allows attackers to identify which apps are being used on the device.
StreamRat can also log what the victim types and keep track of which app is in the foreground. Every time the victim switches to a different app, the malware can report the app package name to the server, so the attacker knows which app the victim is using.
StreamRat can also capture screen lock patterns or PINs, potentially allowing the attacker to get into the victim’s phone even when it’s locked.
Screen viewing
This is perhaps the most dangerous consequence of StreamRat. The malware uses three different ways to see what’s going on on the victim’s screen.
- The first is VNC mode, which uses Android’s built-in screen-sharing feature called MediaProjection. StreamRat can interact with the screen-sharing permission dialog and select full-screen capture. However, Android usually shows a screen-sharing indicator in the status bar, which can alert you.
- This is why there’s a second, hidden VNC mode, which takes a screenshot of your screen every 200 milliseconds. There’s nothing visible that could directly alert you that someone is watching your screen every one-fifth of a second.
- A third method called the Accessibility Node Viewer could allow StreamRat to read the structure of everything displayed on the screen, package it as structured data, and send it to the attacker’s server. This is a fast and lightweight way to collect information displayed on the device, including text.
Remote control
An attacker could use a victim’s phone as if it were their own. They can tap anywhere on the screen, swipe between two points, and interact with the device remotely through Accessibility Services.
Attackers may also type by pasting text into a field, giving them another way to interact with apps on the victim’s device. This could potentially allow them to enter sensitive information or perform actions inside banking and other apps.
Phishing overlays
StreamRat attackers could also use fake screens placed on top of real apps, called overlays, to trick the victim into giving away their credentials. For instance, when you open your banking app, StreamRat can show you a fake overlay mimicking your banking app’s interface.
You may enter your user ID, password, and two-factor authentication details on the screen, trusting it to be the legitimate app. The fake overlay can pass whatever information the victim enters back to the malware, hiding the attack from the victim, much like a phishing page.
Hiding the attack from victims
All of this can happen without the victim immediately noticing anything wrong. StreamRat could hide the attack by using cover screens controlled from the attacker panel’s maintenance section. This black overlay could cover about 98% of the screen and block the victim’s touches. What the victim sees is essentially a black or fake update screen, while the attacker can continue to control the device remotely.
What can you do to protect yourself
There are several things you can do to protect your Android device from StreamRat.
- Never download apps from unknown sources: Make sure you only download apps from the official Google Play Store or other trusted sources, and not from unverified third-party sources.
- Beware of the permissions you grant to apps: A streaming app shouldn’t require Accessibility access or open a new VPN connection. These are red flags that you shouldn’t ignore. Also, check the permissions you have granted to other apps from time to time and revoke any additional access that’s not required for an app’s functioning.
- Keep Google Play Protect switched on: Play Protect is enabled by default on Play Protect-certified Android devices and checks apps installed from unknown sources. Although StreamRat’s internet-blocking trick is designed to interfere with cloud-based security checks, it doesn’t completely disable Play Protect, which can still detect some known harmful apps offline.
- Use a third-party antivirus program: A good antivirus solution can provide an additional layer of protection against StreamRat by detecting malicious apps or suspicious files before they are installed on your device. It can also help flag malicious websites and downloads that could lead to the malware.
If you believe that your phone has already been infected by StreamRat, immediately cut off the attacker’s access by turning on airplane mode, which can help stop the malware from communicating with the attacker’s server.
Then go to Settings and Accessibility and switch off any services that you don’t recognize, and then uninstall the suspicious app, including both the streaming app and anything that appeared after it.
After this, change all your banking passwords. Make sure you set a strong, unique password each time, as well as changing your email and social media passwords and setting a new phone PIN or pattern. You can both change and store your passwords easily using a password manager.
A factory reset may also be worth considering if you want to thoroughly clean your device of malware. You could also consider an identity theft protection service that scans known data breach databases and the dark web for your information and alerts you if it finds it.
The bottom line
StreamRat advertises free streaming services, but once inside your system, it could allow attackers to use your phone as if it were their own. They can steal login details, read text on your screen, capture banking credentials, hijack login sessions, and even capture your phone’s PIN or pattern.
That said, you can largely avoid this type of malware attack with good cyber hygiene. Do not fall for the promise of free streaming and download apps from third-party sources, and pay close attention to the kind of permissions a newly installed app asks for. A streaming app shouldn’t need Accessibility access or a VPN connection.