A newly discovered Android banking trojan named Sturnus has emerged, targeting financial institutions in Europe and demonstrating advanced capabilities beyond typical mobile malware. Sturnus can capture messages from end-to-end encrypted messaging apps such as Signal, WhatsApp, and Telegram by accessing content after decryption directly from the device screen. The malware also enables full device takeover, credential theft through region-specific HTML overlays, and real-time remote control via VNC sessions. Infection typically begins with malicious APKs disguised as legitimate apps like Google Chrome or Preemix Box, and the malware abuses Android Accessibility services to monitor user activity, capture keystrokes, and manipulate the device interface.
Sturnus communicates with its command-and-control infrastructure using a combination of plaintext, RSA, and AES-encrypted channels, establishing secure connections for both data exfiltration and live monitoring. Once installed, it registers the victim device through a cryptographic exchange and can obtain Device Administrator privileges, allowing it to track password changes, lock the device, and maintain persistence. The trojan is currently under active development and is believed to be distributed via malvertising or direct messages, with researchers noting its private operation and ongoing evaluation phase. Security experts warn that Sturnus represents a significant escalation in Android banking malware sophistication, particularly due to its ability to bypass encrypted messaging protections and facilitate financial fraud.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Analysis published with the discovery said Sturnus was being distributed in low volumes and appeared to be in an evaluation phase, but its modular design and existing bank-targeting templates suggested operators were preparing for a larger campaign. Reports also noted its use of plaintext, AES, and RSA-protected communications with command-and-control infrastructure.
Researchers reported that Sturnus includes region-specific banking overlays aimed at financial institutions in Southern and Central Europe, indicating a focus on banking credential theft and transaction fraud. The malware was said to support remote control through VNC-like capabilities and conceal attacker actions with full-screen overlays.
Public reporting disclosed that Sturnus can access message content from Signal, WhatsApp, and Telegram after decryption on the device, effectively bypassing end-to-end encryption protections at the endpoint. The malware was also described as capable of screen capture, UI monitoring, and remote interaction with the victim device.
ThreatFabric identified a new Android banking trojan dubbed Sturnus that steals banking credentials, abuses Android accessibility features, and can take near-total control of infected devices. Researchers assessed it as being in development or limited testing rather than a fully scaled campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourceasec.ahnlab.com
Open sourcehackread.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.