Sturnus, the banking trojan for Android that spies on your chats and controls your mobile phone

  • Sturnus intercepts messages from WhatsApp, Telegram, and Signal using Accessibility permissions on Android.
  • It steals banking credentials with fake overlays and allows VNC-type remote control.
  • It is distributed through disguised APKs and phishing campaigns; possible use of malvertising.
  • It targets Central and Southern Europe; it is operational but in an early stage of deployment.

Sturnus Android banking trojan

The cybersecurity community has focused its attention on Sturnus, a banking Trojan for Android that combines financial fraud techniques with communications espionage. This threat can read conversations on WhatsApp, Telegram, or Signal immediately after the applications decrypt them on the device, and also gives attackers almost complete remote control of the terminal.

ThreatFabric researchers describe a fully functional, albeit early-stage , piece of software capable of stealing credentials through overlays, logging keystrokes, and remotely operating mobile devices. Currently, its activity has been detected primarily in Central and Southern Europe, an area where users and financial institutions should exercise extreme caution against other threats such as PlayPraetor.

What is Sturnus and how does it work?

Sturnus Android banking trojan

The key to Sturnus' success lies in its abuse of the Android Accessibility Service , which allows it to see the same thing on the user's screen and highlights the importance of controlling sideloading in Android . Thus, when a messaging app is opened, the malware waits for the content to appear and captures it, effectively bypassing end-to-end encryption without breaking it.

In addition to spying on chats, this Trojan deploys overlay attacks that mimic mobile banking logins to steal credentials. It can monitor which app is in the foreground, record typed text, and display fake forms to trick victims.

Another key component of Sturnus's arsenal is its VNC-like remote control module . Through an encrypted channel, the attacker can press buttons, type, navigate menus, approve transactions, or change settings. To conceal their activity, they employ visual tricks such as covering the screen with a black overlay or displaying a fake system update while operating in the background.

The impact goes beyond password theft: the ability to read shared conversations and documents exposes users to added risks, such as blackmail or subsequent fraud, while also facilitating stealthy movements within the compromised device.

Infection vector and communication with the server

Sturnus Android banking trojan

The detected infections begin when the victim installs a malicious APK disguised as legitimate apps , such as Google Chrome or an app called Preemix Box. Although the exact method varies, phishing campaigns have been observed, and the use of malvertising to drive downloads from outside the official store is suspected.

Once inside, Sturnus requests Accessibility Service permissions and device administrator privileges . With this combination, it can read text on the screen, simulate gestures, record input, and make uninstallation extremely difficult, remaining persistent on the system.

The malware performs an initial registration with its command and control (C2) infrastructure and establishes mixed communication channels : it combines plaintext exchanges with RSA and AES encryption depending on the phase of the operation. Connections via HTTPS and an additional channel using encrypted WebSockets for real-time commands and data exfiltration have been observed.

According to ThreatFabric, Sturnus features a modular architecture and sustained development , presumably under the management of a private company. This model facilitates rapid updates, the addition of new features, and adaptation to defensive measures, including the silent installation or removal of apps.

Scope in Europe and protection measures

Sturnus Android banking trojan

For now, Sturnus operators appear to be focusing on financial institution clients in Central and Southern Europe , with low-volume campaigns suggesting a testing phase before wider expansion. Nevertheless, its observed capabilities place it among the most complex mobile threats currently available.

If the trials are successful, it is possible that the malware will try to expand its reach to other European countries , including the Spanish market, taking advantage of its screen access and controls to bypass security and multifactor barriers.

Practical recommendations to reduce risk:

  • Avoid installing APKs from outside of Google Play and be wary of download links received via SMS, email or messaging.
  • Review and limit the permissions of Accessibility Service strictly necessary apps.
  • Keep your system and apps updated, active Play Protect and check permits granted regularly.
  • Activate additional secure banking measures: 2FA/MFA, activity alerts and out-of-band validations.

If you suspect something is amiss, act quickly: temporarily disconnect data , notify your bank to block transactions, analyze your device with a reputable solution, revoke accessibility permissions, and if there are still indications of wrongdoing, consider a factory reset and changing your passwords.

The combination of message reading after decryption, live remote control, and convincing bank overlays makes Sturnus a formidable adversary. Although its operators are still proceeding cautiously in Europe, the breadth of its techniques necessitates heightened vigilance and the implementation of best practices before these campaigns gain traction.

Pre-installed Android malware
Related article:
Android and the risk of pre-installed malware: a growing global threat

Add as preferred source in Google