New Sturnus Trojan on Android: Steals Signal and Telegram messages, bypasses encryption, and takes full control of the device

November 27, 2025  19:26

Evidence of an advanced banking trojan known as Sturnus has been found on Android smartphones. According to Android Authority, citing a report from ThreatFabric, the malware not only steals on-screen data but also allows attackers to fully take over the device. The trojan was named after the starling (Sturnus vulgaris) for its “imitative” abilities. It disguises itself as popular apps such as Google Chrome and spreads through malicious APK files. For now, the attacks appear to be in a testing phase, but experts warn that this is likely a precursor to large-scale campaigns. Below is an overview of how the threat works and how users can protect themselves.

How Sturnus Works: From Disguise to Full Device Takeover

Sturnus is not just spyware but a complete banking trojan equipped with multiple tools. It spreads through phishing APKs disguised as items such as “Chrome updates” or “Preemix Box.” Once installed, the malware requests access to the Accessibility Service, enabling it to read the screen, intercept taps, and capture keyboard input. One of its key techniques is the capture of on-screen content after it has been decrypted, which lets it bypass end-to-end encryption in messengers such as Signal, WhatsApp, and Telegram.

For example, when a user opens a chat in Signal, Sturnus captures the text directly from the display, at the point when the device has already decrypted it. The trojan also monitors banking apps and displays fake overlays—counterfeit login screens—to steal credentials and payment card information. Additional capabilities include:

  • Full remote control via VNC sessions, allowing attackers to view and manipulate the screen in real time
  • Keylogging and user interface monitoring to record all interactions
  • A black-screen overlay that hides malicious activity, such as unauthorized money transfers

Communication with the command-and-control (C2) server takes place over a mixed channel using plaintext, AES, and RSA encryption via WebSocket and HTTP, which makes the trojan resistant to interception. Attacks have been recorded in Southern and Central Europe (including Brazil, Italy, and Poland), with templates tailored for local banks such as Banco do Brasil and Itaú.

Connection to Landfall: A Wave of Android Spyware

Sturnus is not the only active threat. On November 9, TechCrunch reported on Landfall, new spyware analyzed by Palo Alto Networks Unit 42 that exploits the zero-day vulnerability CVE-2025-21042 in Samsung Galaxy devices (S22–S24, Z Fold4/Flip4). The campaign began in July 2024 and lasted nine months. Malicious DNG images—with embedded ZIP payloads containing the exploit—were sent via WhatsApp, enabling zero-click infection. Landfall steals photos, contacts, SMS messages, call recordings, and location data. Researchers suggested that it resembles tools used in commercial cyberespionage, possibly linked to vendors such as NSO or Stealth Falcon, which has connections to the UAE.

Both Sturnus and Landfall illustrate a growing trend: Android has become a primary target for spyware, largely due to its widespread adoption (99% in developing markets). Google has already strengthened its defenses through Play Protect and by limiting sideloading, but experts at ThreatFabric and Unit 42 continue to advise caution with APKs from unknown sources.

How to Protect Yourself: Simple Steps for Android Users

  • Install apps only from Google Play and disable “Unknown Sources” in the settings
  • Enable Google Play Protect and two-factor authentication for accounts
  • Use antivirus tools such as Malwarebytes or Bitdefender Mobile, which can detect overlay attacks
  • Avoid opening suspicious links in WhatsApp; scan APK files on VirusTotal before installing
  • Keep your system updated: patches for CVE-2025-21042 were released in April 2025
  • For businesses: segment devices and monitor Accessibility permissions

If you suspect infection, perform a factory reset or contact a service center.

Summary

The Sturnus trojan for Android steals decrypted messages from Signal, Telegram, and WhatsApp, harvests banking credentials, and enables full remote control through screen streaming. It spreads via APKs disguised as Chrome and is currently in a testing phase, but already active in Europe. Meanwhile, Landfall—active since July 2024—uses a Samsung zero-day to conduct espionage. Protect yourself with Play Store installations, antivirus tools, and regular updates. Android remains under heavy attack, so caution is essential to avoid data loss.


 
 
 
 
  • Archive