Android Devices Vulnerable to New ‘Sturnus’ Malware That Attacks Bank Apps, Bypass E2E Encryption: Report

Sturnus, an Android banking trojan, was reportedly spotted by MTI Security researchers.

Advertisement
Written by Dhruv Raghav, Edited by Rohan Pal | Updated: 26 November 2025 11:04 IST
Highlights
  • Sturnus can read a user’s chats without breaking encryption
  • Sturnus is identified to be a private Android Trojan malware
  • The malware can black out a user’s screen

Researchers warn Android users of wider, large scale Sturnus attacks

Photo Credit: Unsplash/ Desola Lanre-Ologun

Android devices are vulnerable to a newly-found malware, dubbed Sturnus, which can access a user's banking credentials, according to a report citing cybersecurity researchers. It is also said to be capable of reading a user's end-to-end encrypted chats on various instant messaging services, like WhatsApp, Telegram, and Signal, without breaching the encryption code. Termed as an Android Banking Trojan, the malware is primarily targeting users in Southern and Central European countries, the report added. However, Google has yet to release a new security patch that would fix the vulnerabilities being leveraged by the trojan.

Sturnus Can Create a Fake Login Page to Access a User's Banking Credentials

ThreatFabric, a publication that focuses on cyberattacks and software vulnerabilities, reports that MTI Security researchers have identified a new Android Banking Trojan, called Sturnus. The malware is capable of replicating the login pages of various banking apps on a user's phone, compelling them to log in to steal their banking credentials. Moreover, it grants “extensive remote” access to the attackers, which allows them to “observe all user activity”.

Sturnus also enables the bad actors to “inject” text without being in physical contact with the Android device. They can also remotely black out the screens of devices to “execute fraudulent transactions in the background”. By making the screen blank, a user does not get to know about said transactions till the money has actually been transferred to an account.

Advertisement

Another concerning factor is that Sturnus can give attackers access to a user's end-to-end encrypted messages. The malware does not need a key to decrypt codes, as it can read the messages after they have been decrypted by capturing the screen of an Android device. It can reportedly “monitor communications” done through WhatsApp, Telegram, and Signal. All three apps provide end-to-end encryption, claiming that even they can't access a user's messages.

Advertisement

The report added that Sturnus' makers are primarily targeting victims in Southern and Central European countries. The researchers believe that the Android Banking Trojan is still in its early stages, and the attackers could still be evaluating and tuning the malware, as only a “few” victims have been spotted so far. The bad actors are reportedly conducting “short, intermittent” attack campaigns. However, the researchers warn that there could be large scale and widespread attacks soon.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. iPhone 18 Pro Models Could Feature a Redesigned, Smaller Dynamic Island
  2. Marvel's Wolverine Launch Date Confirmed, Will Release 2 Months Before GTA 6
  3. iQOO 15R Launched in India With Snapdragon 8 Gen 5 SoC, These Other Features
  4. iPhone 18 Pro Could Launch With This Notable Selfie Camera Upgrade
  5. iQOO Z11x Listed on Geekbench With This MediaTek Dimensity Chipset
  6. Samsung Galaxy Unpacked Today: How to Watch Galaxy S26 Series Launch Live
  7. Nike Launches Pegasus 42, ACG Pegasus Trail Running Shoes in India
  8. Xiaomi 17, Xiaomi 17 Ultra Global and Indian Colourways Confirmed
  1. Marvel's Wolverine Will Launch on September 15, 2026, Insomniac Games Confirms
  2. Xiaomi UltraThin Magnetic Power Bank 5000 15W Launched Globally: Price, Compatibility
  3. MacBook Pro With OLED Touchscreen, Dynamic Island Said to Launch Earlier Than Expected
  4. Oppo Find N6 Leaked Images Hint at Two Colourways; Minor Design Updates Expected
  5. iPhone 18 Pro, iPhone 18 Pro to Feature Redesigned Dynamic Island With Smaller Notch: Report
  6. OnePlus 15R Price in India Could Be Hiked in March, Tipster Claims
  7. Samsung Galaxy Unpacked Event Today: How to Watch Galaxy S26 Series, Galaxy Buds 4 Series Launch Live
  8. Nike Pegasus 42 Running Shoes Launched in India With New Air Zoom Unit, Nike ACG Pegasus Trail Tags Along
  9. Chandra Detects Giant X-Ray Bubble Around Young Sun-Like Star HD 61005
  10. Honor Magic V6 Design, Red Colourway Teased; Company Touts Durability of Magic V6 Hinge
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.