A new Android banking trojan named Sturnus can capture communication from end-to-end encrypted messaging platforms like Signal, WhatsApp, and Telegram, as well as take complete control of the device. Although still under development, the malware is fully functional and has been configured to target accounts at multiple financial organizations in Europe by using "region-specific overlay templates." Sturnus is a more advanced threat than current Android malware families, using a mix of plaintext, RSA, and AES-encrypted communication with the command-and-control (C2) server. A report from online fraud prevention and threat intelligence solutions ThreaFabric explains that Sturnus can steal messages from secure messaging apps after the decryption stage by capturing the content from the device screen. The malware can also steal banking account credentials using HTML overlays and includes support for full, real-time remote control via VNC session. ThreatFabric told BleepinComputer that the infection starts with downloading malicious Android APK files disguised as Google Chrome or Preemix Box applications. The researchers have not discovered how the malware is distributed but they believe that malvertising or direct messages are likely methods. After installation, the malware connects to the C2 infrastructure to register the victim via a cryptographic exchange. It establishes an encrypted HTTPS channel for commands and data exfiltration, and an AES-encrypted WebSocket channel for re...
Multi-threat Android malware Sturnus steals Signal, WhatsApp messages
BleepingComputer
·Bill Toulas
·Published Nov 20, 2025
·Updated
Affected Software
1 affected component
Android banking trojan Sturnus
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new Android banking trojan named Sturnus that steals messages from secure messaging apps.
2
What security implications are discussed in the article?
The article highlights that Sturnus can compromise end-to-end encrypted communication and gain full control of affected devices.
3
What messaging apps are specifically targeted by the Sturnus malware?
Sturnus targets messaging platforms including Signal, WhatsApp, and Telegram.
4
What capabilities does the Sturnus malware possess?
Sturnus can capture messages from encrypted apps as well as take complete control over infected Android devices.
5
Is the Sturnus malware fully developed or still in development?
The article mentions that Sturnus is still under development.