Sturnus is a privately operated Android banking trojan designed for financial fraud, credential theft, device surveillance, and remote takeover. It targets financial institutions in Southern and Central Europe using region-specific phishing overlays that imitate legitimate banking login interfaces. It abuses Android Accessibility Services to capture entered text, monitor interface events, collect UI-tree data, and reconstruct on-screen activity. This enables theft of banking credentials, device-unlock PINs, and passwords.
Sturnus can capture chat content from WhatsApp, Telegram, and Signal after those applications decrypt and render it on the device, bypassing the practical confidentiality protection of end-to-end encryption without cryptographically breaking it. It supports VNC-style remote sessions and an Accessibility-based control channel for actions including clicks, text entry, scrolling, application launches, and permission confirmations. Operators can use full-screen black or fake-update overlays to conceal fraudulent activity while remotely interacting with the device.
The malware uses Device Administrator privileges and Accessibility monitoring to impede removal, including detecting attempts to revoke its administrative status and navigating away from relevant settings. It also gathers device, hardware, network, sensor, installed-application, and security-environment information, including indicators related to rooting, ADB, developer mode, and SELinux. Command-and-control communications use HTTP and WebSocket channels protected through a combination of RSA and AES encryption. Observed activity was limited and assessed as development or testing, although the malware was fully functional and prepared for targeted European banking campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
"New Sturnus Android Malware Reads WhatsApp, Telegram, Signal Chats via Accessibility Abuse" / "bypasses end-to-end encryption"
The malware then generates a 256-bit AES key locally, encrypts it using RSA/ECB/OAEPWithSHA-1AndMGF1Padding, and sends the encrypted key back... all further communication is protected with AES encryption
DELETE_ALL_SMS Deletes all SMS messages on the device. DELETE_SMS Deletes a specific SMS message. DELETE_ALL_CALLS Deletes the entire call log. DELETE_CALL Deletes a specific call entry.
By capturing content directly from the device screen after decryption, Sturnus can monitor communications via WhatsApp, Telegram, and Signal.
It also monitors security-relevant settings such as developer mode, ADB debugging, SELinux state, and the device’s patch level, reporting any change immediately to the operators.
This enables attackers to reconstruct full user activity even when screen capture is blocked by FLAG_SECURE or when network conditions prevent live video transmission.
By capturing content directly from the device screen after decryption, Sturnus can monitor communications via WhatsApp, Telegram, and Signal.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned solely as a comparison point for StreamRat's C2 protocol.
Android banking trojan enabling credential theft and device takeover; captures content from screen post-decryption to bypass encrypted messaging protections.
Android malware that intercepts decrypted messages from messaging apps such as WhatsApp, Telegram, and Signal.
An Android banking trojan with capabilities to steal banking credentials and dump chats from secure messaging apps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.