logo

New Trojan “Sturnus” Elevates Android Messaging and Banking Risks

ID: 5102a737-8802-59ab-bd7b-7fe1df65d6b3

STIX ID: report--5102a737-8802-59ab-bd7b-7fe1df65d6b3

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2025-12-15

Date Updated: 2026-05-01

...
...

Sturnus is a newly disclosed Android banking trojan capable of full device takeover: it captures decrypted chats from apps like WhatsApp, Telegram, and Signal by reading screen output and performs overlay attacks to steal banking credentials and enable fraudulent transactions. The malware is typically delivered via malicious APKs or social-engineering lures, underscoring elevated risks to mobile endpoints even when secure messaging is used.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.