Malware

Android banking trojan Sturnus intercepts encrypted messages

Cyber security concept. Toy horse on a digital screen, symbolizes the attack of the Trojan virus. 3D illustration.

As reported by The Record, a new Android banking trojan named Sturnus has been discovered by cybersecurity researchers. This malware is capable of intercepting messages from popular apps like WhatsApp, Telegram and Signal after they have been decrypted.

The Sturnus trojan, identified by Dutch cybersecurity firm ThreatFabric, is designed to steal banking credentials through convincing fake login screens and gain remote control over infected devices. It can monitor real-time phone activity, access decrypted data from legitimate apps, inject text, observe user actions and execute transactions while concealing its operations with a full-screen overlay.

The malware, although currently in a developmental or limited testing phase, is already configured with templates targeting banks in Southern and Central Europe, indicating potential preparations for a broader attack. The emergence of Sturnus adds to the growing trend of sophisticated Android banking trojans like Herodotus and Crocodilus.

Source: The Record

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds