logo

Multi-threat Android malware Sturnus steals Signal, WhatsApp messages

ID: d6ed9e8a-3c25-50c8-bf5a-9e210a4a4933

STIX ID: report--d6ed9e8a-3c25-50c8-bf5a-9e210a4a4933

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-11-20

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

A ThreatFabric report describes Sturnus, an advanced Android banking trojan that captures decrypted messages from Signal/WhatsApp/Telegram, uses Accessibility services and Device Administrator privileges to perform full device takeover, deploys HTML overlays and hidden VNC-driven actions for fraudulent banking transactions, and communicates with C2 using plaintext, RSA, AES, HTTPS and AES-encrypted WebSockets; currently observed in low-volume tests targeting Southern and Central Europe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.