Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
financial-sector-threatcredential-stealer-activityremote-access-implantcommand-and-control-method

Sturnus Android Banking Trojan Enables Device Takeover and Encrypted Chat Theft

Updated 3mo agoFirst seen Nov 20, 20257 sources

A newly discovered Android banking trojan named Sturnus has emerged, targeting financial institutions in Europe and demonstrating advanced capabilities beyond typical mobile malware. Sturnus can capture messages from end-to-end encrypted messaging apps such as Signal, WhatsApp, and Telegram by accessing content after decryption directly from the device screen. The malware also enables full device takeover, credential theft through region-specific HTML overlays, and real-time remote control via VNC sessions. Infection typically begins with malicious APKs disguised as legitimate apps like Google Chrome or Preemix Box, and the malware abuses Android Accessibility services to monitor user activity, capture keystrokes, and manipulate the device interface.

Sturnus communicates with its command-and-control infrastructure using a combination of plaintext, RSA, and AES-encrypted channels, establishing secure connections for both data exfiltration and live monitoring. Once installed, it registers the victim device through a cryptographic exchange and can obtain Device Administrator privileges, allowing it to track password changes, lock the device, and maintain persistence. The trojan is currently under active development and is believed to be distributed via malvertising or direct messages, with researchers noting its private operation and ongoing evaluation phase. Security experts warn that Sturnus represents a significant escalation in Android banking malware sophistication, particularly due to its ability to bypass encrypted messaging protections and facilitate financial fraud.

Share:
Sturnus Android Banking Trojan Enables Device Takeover and Encrypted Chat Theft
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Nov 20, 20257mo ago

Researchers warn Sturnus may be preparing for broader deployment

Analysis published with the discovery said Sturnus was being distributed in low volumes and appeared to be in an evaluation phase, but its modular design and existing bank-targeting templates suggested operators were preparing for a larger campaign. Reports also noted its use of plaintext, AES, and RSA-protected communications with command-and-control infrastructure.

Analysis links Sturnus to financial fraud targeting banks in Central and Southern Europe

Researchers reported that Sturnus includes region-specific banking overlays aimed at financial institutions in Southern and Central Europe, indicating a focus on banking credential theft and transaction fraud. The malware was said to support remote control through VNC-like capabilities and conceal attacker actions with full-screen overlays.

Researchers reveal Sturnus can capture decrypted chats from messaging apps

Public reporting disclosed that Sturnus can access message content from Signal, WhatsApp, and Telegram after decryption on the device, effectively bypassing end-to-end encryption protections at the endpoint. The malware was also described as capable of screen capture, UI monitoring, and remote interaction with the victim device.

ThreatFabric discovers the Sturnus Android banking trojan

ThreatFabric identified a new Android banking trojan dubbed Sturnus that steals banking credentials, abuses Android accessibility features, and can take near-total control of infected devices. Researchers assessed it as being in development or limited testing rather than a fully scaled campaign.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Affected products
4 linked
AndroidTelegramWhatsappSignal
Organizations
11 linked
ThreatFabricGoogleBleepingComputerRecorded FutureThe Kyiv PostMeta PlatformsTelegramSignal MessengerThe Kyiv IndependentForbes UkraineSifted
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.