New Trojan is coming — Sturnus
MTI Security researchers have identified Sturnus, a privately operated Android banking trojan. This malware supports a broad range of…
New Trojan is coming — Sturnus
Photo by Nahel Hadi on Unsplash
MTI Security researchers have identified Sturnus, a privately operated Android banking trojan. This malware supports a broad range of fraud-related capabilities, including full device takeover. A key differentiator is its ability to bypass encrypted messaging. By capturing content directly from the device screen after decryption, Sturnus can monitor communications via WhatsApp, Telegram, and Signal.
Sturnus is an advanced Android Banking Trojan that allows attackers to fully take over infected devices and bypass encrypted messaging apps. By reading text directly from the screen and using fake overlays, it steals credentials, intercepts private chats on platforms like WhatsApp and Signal, and drains bank accounts.
While analysis indicates this operation is currently in a development or limited testing phase, Sturnus has already been configured with targeted attacks against financial institutions across Southern and Central Europe, suggesting preparations for a broader campaign. While we emphasize that the malware is likely in its pre-deployment state, it is also currently fully functional, and in aspects such as its communication protocol and device support, it is more advanced than current and more established malware families.
ThreatFabric mapped the capabilities of this new malware family according to the MITRE ATT&CK matrix, and you can find the corresponding techniques used:
Target & Victimology
Current evidence indicates that Sturnus.A is still in an evaluation and tuning phase, with relatively few samples and short, intermittent campaigns rather than sustained large-scale activity. The victimology so far points to targets primarily located in Southern and Central Europe, where we have observed region-specific overlay templates. In parallel, the malware’s behavior shows a clear focus on compromising widely used secure messaging platforms such as WhatsApp, Telegram, and Signal, suggesting that the operators are testing its ability to capture sensitive communications across different environments. Although the spread remains limited at this stage, the combination of targeted geography and high-value application focus implies that the attackers are refining their tooling ahead of broader or more coordinated operations.
메타데이터
- post_id
- 7bdfe03b4dbf
- slug
- new-trojan-is-coming-sturnus-7bdfe03b4dbf
- url
- https://medium.com/@devilwhite496/new-trojan-is-coming-sturnus-7bdfe03b4dbf
- canonical_url
- https://medium.com/@devilwhite496/new-trojan-is-coming-sturnus-7bdfe03b4dbf
- author_url
- https://medium.com/@devilwhite496
- status
- ok
- fetched_at
- 2026-07-15 02:09:20