HomeSecuritySturnus banking trojan steals messages from Signal & WhatsApp

Sturnus banking trojan steals messages from Signal & WhatsApp

A new and highly sophisticated Android banking trojan, dubbed Sturnus, has caught the attention of cybersecurity experts across Europe. Sturnus initially appeared in targeted attacks in Southern and Central Europe, but is now believed to be one of the most dangerous threats to mobile device users and online banking.

Sturnus banking trojan

Modern banking malware with new monitoring capabilities

Unlike classic banking trojans, Sturnus doesn’t limit itself to stealing credentials via phishing screens. It brings to the fore a new level of threat: monitoring encrypted messaging like WhatsApp, Telegram, and Signal — right after they’ve been decrypted on the device.

See also: Python-based WhatsApp worm spreads Eternidade Stealer

In other words, the malware "sees" exactly what the user sees, completely bypassing the end-to-end encryption of the applications.

This technique allows him to:

  • Records messages and notifications
  • Monitors conversations in real time
  • Takes screenshots without being noticed

This upgrade brings Sturnus a few steps ahead of many well-known banking trojans such as Cerberus, Anatsa, and Xenomorph.

Complete takeover of the device without the user realizing it

According to Threat Fabric, the malware can achieve full remote access to the device. Attackers are able to:

  • They fully control the screen
  • They type remotely
  • Interact with banking applications
  • Interfere with notifications
  • They black out the screen so the victim doesn't see the illegal activity.

This last feature is the most worrying: the user can hold their device in their hands and not see anything the attacker is doing in the background.

Sturnus typically exploits fake login screens that closely mimic popular banking apps, collecting PINs, 2FA codes, and other sensitive information, which is then used to gain direct access to accounts.

See also: TamperedChef: Malware distribution via fake installers

Sturnus banking trojan steals messages from Signal & WhatsApp

Targeted campaigns in Southern and Central Europe

Although still in limited development, Sturnus is already highly specialized.

Analysts believe the attackers are testing the trojan's capabilities before making it available to wider, global businesses.

The samples found so far are few, but the level of maturity of the malware indicates that its creators have invested significant resources in its development and optimization.

The source of the name: A chaotic communication protocol

Sturnus is named after the common starling, Sturnus vulgaris, a bird known for its abrupt, erratic song changes. Accordingly, the trojan uses a "chaotic" communication model, combining:

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

  • Plain text
  • RSA
  • AES

These alternations between simple and complex messages make detection and analysis by security systems.

How it communicates with the Command & Control server:

  1. It establishes a connection via WebSocket (WSS) and HTTP.
  2. Sends an HTTP POST request for registration.
  3. It receives a UUID and a public RSA key.
  4. It generates an AES 256-bit key and encrypts it with RSA.
  5. All subsequent transmissions are encrypted with AES/CBC/PKCS5Padding.

Each message contains:

  • new initialization vector (IV)
  • encrypted data
  • message type headers, message length data and client UUIDs

This is one of the most complex communication protocols that mobile threat analysts have seen in years.

See also: Nova Stealer: Steals crypto wallet data from macOS users

What does the emergence of Sturnus mean for users and banks?

Sturnus shows a worrying trend: malware creators are now investing in monitoring encrypted applications — something that seemed particularly difficult until a few years ago.

Although Sturnus is still in the "optimization" phase, experts fear that it may very soon join the so-called premium trojans, i.e. the most dangerous tools that are circulated on underground forums and sold as a service (malware-as-a-service).

Sturnus banking trojan steals messages from Signal & WhatsApp

How can users be protected?

Experts recommend:

  • Install apps only from Google Play
  • Checking application access permissions
  • Disable “Accessibility” services for apps that are not required
  • Use mobile antivirus from trusted vendors
  • Avoid sideloading APKs from links or emails

In addition, banks are called upon to enhance the detection of suspicious connection patterns, as well as to implement mechanisms that prevent remote interaction with banking applications.

Sturnus is one of the most worrying new threats for 2025. With full remote access capabilities, messaging application , and a sophisticated cryptographic protocol, it shows the direction in which modern banking trojans are evolving.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS