Drooid Logo
Back to story perspectives

Full Breakdown

Sturnus: A New Android Banking Trojan Threatening Secure Messaging

11/21/2025, 8:38:40 PM

Overview of Sturnus Malware

Cybersecurity researchers have identified a new Android banking trojan named Sturnus, which poses significant risks to users of secure messaging applications such as WhatsApp, Telegram, and Signal. Developed by the Dutch mobile security firm ThreatFabric, Sturnus is designed to conduct credential theft and enable full device takeover, particularly targeting financial institutions in Southern and Central Europe. Although currently assessed to be in a limited testing phase, its capabilities suggest preparation for broader malicious operations.

Key Features and Functionality

Sturnus employs advanced techniques to bypass the encryption protections of secure messaging apps. Instead of breaking encryption, it captures decrypted message content directly from the device screen using Android's Accessibility Services. This allows attackers to monitor real-time communications, including contacts and full conversation threads, effectively sidestepping the security measures these applications provide.

The malware also features overlay attacks, displaying fake login screens that mimic legitimate banking apps to trick users into entering their credentials. Once the credentials are harvested, the overlay is disabled to avoid detection. Additionally, Sturnus can log keystrokes and remotely control the infected device through Virtual Network Computing (VNC) sessions, providing attackers with extensive access to the victim's activities.

Targeted Geography and Victim Profile

Sturnus specifically targets users in Southern and Central Europe, utilizing region-specific overlay templates to enhance its phishing attempts. The malware's design indicates a focused strategy aimed at high-value financial applications, suggesting that its operators are refining their tools for more coordinated attacks in the future.

Official Statements & Responses

ThreatFabric has expressed concern regarding the sophistication of Sturnus, noting that its combination of overlay-based credential theft, message monitoring, and extensive keylogging creates a comprehensive threat to victims' financial security and privacy. The firm emphasizes the importance of vigilance among users, advising them to avoid sideloading applications from unofficial sources and to regularly check installed apps for unusual Accessibility Service permissions.

Criticism & Opposition

While Sturnus is still under development, its advanced features have raised alarms among cybersecurity experts. Critics argue that the malware's ability to exploit Accessibility Services poses a significant challenge for user privacy and security, as it can operate without raising immediate suspicion. The reliance on user permissions, often granted without careful consideration, is seen as a critical vulnerability that could lead to widespread exploitation.

What's Next?

As Sturnus continues to evolve, cybersecurity experts anticipate that its operators may launch more extensive campaigns targeting financial institutions and users of secure messaging applications. Ongoing monitoring and research into the malware's development will be crucial in understanding its potential impact and in formulating effective countermeasures.

Verbatim Quotes

  • “Sturnus represents a sophisticated and comprehensive threat, implementing multiple attack vectors that provide attackers with near-complete control over infected devices.” — ThreatFabric
  • “This makes the capability particularly dangerous: it completely sidesteps end-to-end encryption by accessing messages after they are decrypted by the legitimate app, giving the attacker a direct view into supposedly private conversations,” — ThreatFabric
  • “Because it relies on Accessibility Service logging rather than network interception, the malware can read everything that appears on screen—including contacts, full conversation threads, and the content of incoming and outgoing messages—in real time.” — ThreatFabric
  • “Until its administrator rights are manually revoked, both ordinary uninstallation and removal through tools like ADB are blocked, giving the malware strong protection against cleanup attempts.” — ThreatFabric

In conclusion, Sturnus exemplifies the growing sophistication of Android malware, highlighting the need for users to remain vigilant and proactive in safeguarding their devices against emerging threats.