logo

Sturnus Banking Malware Steals Communications from Signal and WhatsApp, Gaining Full Control of The Device

ID: 284f5294-03c2-5cee-a917-4f248bb5a4b5

STIX ID: report--284f5294-03c2-5cee-a917-4f248bb5a4b5

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-11-20

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Sturnus is a sophisticated Android banking trojan observed in early targeted campaigns in Southern and Central Europe that uses convincing overlay login screens to steal banking credentials and can capture decrypted messages from apps like WhatsApp, Telegram, and Signal by reading the device screen. It provides full remote device takeover (including SMS injection and screen blackout) and uses a layered communication protocol combining plaintext, RSA, and AES over WebSocket/HTTP; researchers report limited samples and intermittent campaigns consistent with an evaluation/tuning phase.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.