Sturnus

Malware type
trojan, credential-stealer, screen-capture, spyware
Family
Malware family
Profile updated
2026-07-07 14:10:12

Targeted industries: financial-services

Context

According to ThreatFabric, Sturnus is a privately operated Android banking trojan. This malware supports a broad range of fraud-related capabilities, including full device takeover. A key differentiator is its ability to bypass encrypted messaging. By capturing content directly from the device screen after decryption, Sturnus can monitor communications via WhatsApp, Telegram, and Signal. The trojan can harvest banking credentials through convincing fake login screens that replicate legitimate banking apps. In addition, it provides attackers with extensive remote control, enabling them to observe all user activity, inject text without physical interaction, and even black out the device screen while executing fraudulent transactions in the background—without the victim’s knowledge.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Sturnus (report)
  • threatfabric.com — Sturnus Banking Trojan Bypassing Whatsapp Telegram And Signal (report)

External references