A new and highly sophisticated Android banking trojan, dubbed Sturnus, has caught the attention of cybersecurity experts across Europe. Sturnus initially appeared in targeted attacks in Southern and Central Europe, but is now believed to be one of the most dangerous threats to mobile device users and online banking.

Modern banking malware with new monitoring capabilities
Unlike classic banking trojans, Sturnus doesn’t limit itself to stealing credentials via phishing screens. It brings to the fore a new level of threat: monitoring encrypted messaging like WhatsApp, Telegram, and Signal — right after they’ve been decrypted on the device.
See also: Python-based WhatsApp worm spreads Eternidade Stealer
In other words, the malware "sees" exactly what the user sees, completely bypassing the end-to-end encryption of the applications.
This technique allows him to:
- Records messages and notifications
- Monitors conversations in real time
- Takes screenshots without being noticed
This upgrade brings Sturnus a few steps ahead of many well-known banking trojans such as Cerberus, Anatsa, and Xenomorph.
Complete takeover of the device without the user realizing it
According to Threat Fabric, the malware can achieve full remote access to the device. Attackers are able to:
- They fully control the screen
- They type remotely
- Interact with banking applications
- Interfere with notifications
- They black out the screen so the victim doesn't see the illegal activity.
This last feature is the most worrying: the user can hold their device in their hands and not see anything the attacker is doing in the background.
Sturnus typically exploits fake login screens that closely mimic popular banking apps, collecting PINs, 2FA codes, and other sensitive information, which is then used to gain direct access to accounts.
See also: TamperedChef: Malware distribution via fake installers

Targeted campaigns in Southern and Central Europe
Although still in limited development, Sturnus is already highly specialized.
Analysts believe the attackers are testing the trojan's capabilities before making it available to wider, global businesses.
The samples found so far are few, but the level of maturity of the malware indicates that its creators have invested significant resources in its development and optimization.
The source of the name: A chaotic communication protocol
Sturnus is named after the common starling, Sturnus vulgaris, a bird known for its abrupt, erratic song changes. Accordingly, the trojan uses a "chaotic" communication model, combining:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Plain text
- RSA
- AES
These alternations between simple and complex messages make detection and analysis by security systems.
How it communicates with the Command & Control server:
- It establishes a connection via WebSocket (WSS) and HTTP.
- Sends an HTTP POST request for registration.
- It receives a UUID and a public RSA key.
- It generates an AES 256-bit key and encrypts it with RSA.
- All subsequent transmissions are encrypted with AES/CBC/PKCS5Padding.
Each message contains:
- new initialization vector (IV)
- encrypted data
- message type headers, message length data and client UUIDs
This is one of the most complex communication protocols that mobile threat analysts have seen in years.
See also: Nova Stealer: Steals crypto wallet data from macOS users
What does the emergence of Sturnus mean for users and banks?
Sturnus shows a worrying trend: malware creators are now investing in monitoring encrypted applications — something that seemed particularly difficult until a few years ago.
Although Sturnus is still in the "optimization" phase, experts fear that it may very soon join the so-called premium trojans, i.e. the most dangerous tools that are circulated on underground forums and sold as a service (malware-as-a-service).

How can users be protected?
Experts recommend:
- Install apps only from Google Play
- Checking application access permissions
- Disable “Accessibility” services for apps that are not required
- Use mobile antivirus from trusted vendors
- Avoid sideloading APKs from links or emails
In addition, banks are called upon to enhance the detection of suspicious connection patterns, as well as to implement mechanisms that prevent remote interaction with banking applications.
Sturnus is one of the most worrying new threats for 2025. With full remote access capabilities, messaging application , and a sophisticated cryptographic protocol, it shows the direction in which modern banking trojans are evolving.
