Sturnus is a privately operated Android banking trojan focused on financial fraud and full device takeover. It targets Android devices and has been observed using region-specific phishing overlays aimed at financial institutions in Southern and Central Europe, indicating a targeted banking-fraud operation rather than indiscriminate mass distribution.
The malware steals banking credentials through convincing fake login screens displayed over legitimate applications. It heavily abuses Android Accessibility Services to monitor interface events, capture user input, log on-screen text, and reconstruct the device’s UI state in real time. This enables operators to observe victim activity, inject text, click interface elements, scroll, launch applications, confirm prompts, and otherwise control the device without physical access.
A notable capability of Sturnus is its ability to bypass the practical protections of end-to-end encrypted messaging applications by collecting content after decryption on the device. It has been reported monitoring communications in WhatsApp, Telegram, and Signal by reading visible interface content and message threads through accessibility-driven UI inspection rather than breaking the encryption itself.
Sturnus also supports near-real-time remote sessions, including VNC-style screen sharing and lower-bandwidth control based on accessibility-derived interface data. Operators can conceal fraudulent actions with full-screen black overlays or fake update screens while conducting transactions, approving dialogs, or interacting with banking workflows in the background. After harvesting credentials for a specific target, the malware can disable the corresponding overlay to reduce suspicion.
For resilience and persistence, Sturnus seeks Android Device Administrator privileges, allowing it to monitor lock-screen activity, password changes, and unlock attempts while making removal more difficult. It can detect attempts to revoke its privileges and interfere with the process through accessibility-driven navigation. The malware also performs extensive device and environment checks, including conditions associated with analysis or tampering, reflecting a mature anti-removal and anti-analysis design.
Its command-and-control architecture uses a hybrid encrypted communications model involving HTTP and WebSocket channels with RSA- and AES-based key exchange and message protection. Researchers have assessed the operation as likely being in an early development or limited-testing phase, but the malware is already fully functional and comparatively advanced for an emerging Android banking trojan.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
"New Sturnus Android Malware Reads WhatsApp, Telegram, Signal Chats via Accessibility Abuse" / "bypasses end-to-end encryption"
The malware then generates a 256-bit AES key locally, encrypts it using RSA/ECB/OAEPWithSHA-1AndMGF1Padding, and sends the encrypted key back... all further communication is protected with AES encryption
DELETE_ALL_SMS Deletes all SMS messages on the device. DELETE_SMS Deletes a specific SMS message. DELETE_ALL_CALLS Deletes the entire call log. DELETE_CALL Deletes a specific call entry.
By capturing content directly from the device screen after decryption, Sturnus can monitor communications via WhatsApp, Telegram, and Signal.
It also monitors security-relevant settings such as developer mode, ADB debugging, SELinux state, and the device’s patch level, reporting any change immediately to the operators.
This enables attackers to reconstruct full user activity even when screen capture is blocked by FLAG_SECURE or when network conditions prevent live video transmission.
By capturing content directly from the device screen after decryption, Sturnus can monitor communications via WhatsApp, Telegram, and Signal.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan enabling credential theft and device takeover; captures content from screen post-decryption to bypass encrypted messaging protections.
Android malware that intercepts decrypted messages from messaging apps such as WhatsApp, Telegram, and Signal.
An Android banking trojan with capabilities to steal banking credentials and dump chats from secure messaging apps.
Sturnus is a mobile banking malware that bypasses encryption in messaging apps like WhatsApp, Telegram, and Signal to steal sensitive information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.