Sturnus Trojan Bypasses Messaging App Security

26 Nov 2025

Sturnus, a newly identified Android banking trojan, can bypass protections of encrypted messaging apps by capturing decrypted messages. This impacts apps such as Signal, Telegram, and WhatsApp.

Malware Techniques and Risks

According to ThreatFabric, Sturnus targets the Android Accessibility Service to capture on-screen data, effectively sidestepping end-to-end encryption. Instead of network interception, Sturnus logs device activity, allowing full control over the device, harvesting banking details, and capturing real-time message data.

  • Sturnus uses a mix of plaintext, RSA, and AES encryption.
  • Communications are sent to a Matrix Push server.
  • Traditional detections are evaded by blending with normal network traffic.

Preventative Measures

The Cybersecurity and Infrastructure Security Agency (CISA) warns of spyware threats against encrypted messaging apps. Common delivery methods include phishing and zero-click exploits. CISA advises users to enable Google Play Protect, avoid unofficial app stores, and restrict Accessibility permissions.

  • Verify group invitations through separate channels.
  • Be cautious of unexpected authentication prompts.
  • Limit the number of linked devices.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6654398
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1389720
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
550565
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
460340
downloads

News and reviews for Mobile Android

CISA Warns of Increasing Messaging App Threats

CISA alerts users to heightened threats against messaging apps like WhatsApp, Telegram, and Signal.

Read more

Android Deals Highlight Major Game Discounts for 2025

9to5Toys reveals Android deals with significant discounts on apps like Rush Rally Origins. Savings for tech enthusiasts.

Read more

Libby Adds AI and Expands Device Compatibility

Libby now includes AI book suggestions and runs on Android e-readers like Onyx Boox and Bigme. Update enhances user experience.

Read more

X Launches Hidden Android Redesign, Offers Subscription Discounts

X unveils a secret Android redesign in version 11.42.0-release.0 and offers discount subscriptions. Available until 2025-12-02 in India and beyond.

Read more

Cryptomining Apps in 2025 Transform Passive Earning

Cryptomining apps in 2025 leverage mobile, cloud tech for ease; key into short-cycle contracts and renewable sources.

Read more

Top Offline Mobile Games to Try in November 2025

Explore the latest offline games for Android and iOS this November. Enjoy roguelike adventures, puzzles, and more without an internet connection.

Read more

Journey Offers Comprehensive Cross-Platform Journaling

Journey app available cross-platform, matches Google's Pixel-only Journal. Flexible design enhances journaling experience.

Read more

Launch Remix Feature in Google Messages

Google Messages adds Remix feature for image generation using Nano Banana model in app, starting 2025-11-26.

Read more

Google Enhances Gemini with 'Projects' Feature

Google's Gemini app is set to gain a 'Projects' feature, enhancing user-focused AI research and organization capabilities.

Read more

Norton Introduces Black Friday Discounts on Security Plans

Norton has launched Black Friday discounts on antivirus and security plans across regions, benefiting individual and business users.

Read more