Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

Sturnus

Sturnus is an Android banking trojan identified by ThreatFabric. It is designed for credential theft and financial fraud, using convincing fake banking login overlays/HTML screens to steal credentials and enabling near-total remote control of infected Android devices. The malware abuses Android Accessibility Services to capture keystrokes, UI elements, and on-screen content, allowing operators to monitor device activity in real time, inject text, press buttons, scroll, launch apps, and reconstruct the device layout remotely. It also supports VNC-style remote control and display capture, and operators can use a black full-screen overlay or fake Android update screen to conceal malicious actions while executing transactions, approving dialogs or MFA prompts, changing settings, or installing apps.

A notable capability of Sturnus is its ability to capture content from end-to-end encrypted messaging applications such as WhatsApp, Telegram, and Signal. Rather than breaking encryption, it reads messages, contacts, and full chat threads after they are decrypted and displayed on the device, using accessibility abuse and screen/UI capture. Sturnus also gathers extensive device profiling data, including installed apps, hardware, sensor, and network information, to adapt its tactics. It can obtain Device Administrator privileges, detect attempts to disable those privileges, navigate users away from relevant settings, and block uninstallation or removal via ADB until admin rights are revoked.

Observed Sturnus artifacts include malicious APKs disguised as Google Chrome (com.klivkfbky.izaybebnx) and Preemix Box (com.uvxuthoq.noscjahae). The malware communicates with remote infrastructure over HTTP/HTTPS and WebSocket, with reporting indicating a mix of plaintext, AES, and RSA-encrypted communications; the name "Sturnus" is noted as referring to this mixed communication pattern. ThreatFabric reported that Sturnus is privately operated, currently in development, evaluation, or limited testing, but already fully functional. It has been configured with region-specific templates targeting banks and financial institutions in Southern and Central Europe, suggesting preparation for broader campaigns.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Persistence

1 technique
T1546.008Accessibility FeaturesEvidence1

"New Sturnus Android Malware Reads WhatsApp, Telegram, Signal Chats via Accessibility Abuse" / "bypasses end-to-end encryption"

Privilege Escalation

1 technique
T1546.008Accessibility FeaturesEvidence1

"New Sturnus Android Malware Reads WhatsApp, Telegram, Signal Chats via Accessibility Abuse" / "bypasses end-to-end encryption"

Credential Access

2 techniques
T1056Input CaptureEvidence1

“Once installed, Sturnus can monitor everything displayed on a phone in real time — including contacts, full message threads and the content of encrypted chats — by accessing data after it has been decrypted by legitimate apps.”

T1056.004Credential API HookingEvidence1

“It can also inject text, observe user activity…”

Collection

3 techniques
T1056Input CaptureEvidence1

“Once installed, Sturnus can monitor everything displayed on a phone in real time — including contacts, full message threads and the content of encrypted chats — by accessing data after it has been decrypted by legitimate apps.”

T1056.004Credential API HookingEvidence1

“It can also inject text, observe user activity…”

T1113Screen CaptureEvidence1

“Once installed, Sturnus can monitor everything displayed on a phone in real time…”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.