There's a new Android malware that has been recently identified as a serious risk for Android phones. Unfortunately, the Trojan focuses on stealing banking information and can capture encrypted messages, even from platforms like WhatsApp and Signal, without the user realizing it did so.
New Android malware found that can steal banking information
ThreatFabric now reports that there is a new Android banking trojan malware dubbed Sturnus. It has been identified by MTI Security researchers as highly capable malware that can even achieve device takeover.
Unfortunately, the virus seems capable of bypassing message encryption. It does so by reportedly capturing content from the device's screen after the messages have been decrypted by apps like WhatsApp, Signal, and Telegram. So no, it's not breaking the encryption, but it's simply recording the decrypted content from the phone's screen.
What's even creepier is that Sturnus can steal login credentials for banking apps. It reportedly does so by displaying fake but convincing login windows. When you enter the credentials on what looks like the login screen of your banking app, these credentials are sent to the malicious users behind the virus.
Image Credit - ThreatFabric
It's also been found that the virus gives attackers significant remote control capabilities. Malicious users can observe your activity, push text to the device, and on top of it all, they can black out the device screen when they do fraudulent transactions.
Luckily, Sturnus has not been deployed at full scale just yet. Reportedly, the malware is currently in development or probably in testing. Some targeted attacks have reportedly been made in Southern and Central Europe.
The publication notes that although the spread is limited at this moment, there are hints that suggest the attackers may be planning a broader attack when their tool gets refined.
However, the fact that we are hearing about it is generally good news. Sturnus has been identified now, and it's highly likely that Google is already working on bumping up Android's defenses against it.
Do you worry about Android malware like this?
Yes — threats like this make me nervous
100%
A little — I stay careful, but it’s still creepy
0%
Not really — I follow security rules and feel safe
0%
No — malware isn’t something I think about much
0%
How to make sure you've done everything you can to protect yourself
First, make sure your phone only installs apps from Google Play or another trusted store. Most malware sneaks in through random APKs or shady links, so avoiding those already cuts a huge part of the risk.
Recommended For You
It also helps to regularly check which apps have access to things like your screen, accessibility settings, or notifications – if something looks off, remove it right away.
Also, turn on two-factor authentication for your banking apps and Google account. Even if someone somehow gets your password, they won't be able to log in without the second step.
Keep your phone updated too, because Google pushes security fixes all the time, and potentially, it's going to send an update that addresses this malware as well. And as boring as it sounds, don't tap on weird links in texts, emails, or random websites. It saves you a lot of trouble, trust me (or trust my mom).
Malware like this is scary, but not worth panicking over
Malware like Sturnus always sounds terrifying at first, but honestly, most people who follow basic security habits will be fine. Malware usually targets users who install random apps or ignore warnings, not someone who just uses their phone normally and keeps it updated.
So yeah, it's creepy, but it's also something you can stay safe from with a bit of care.
Personally, I just use the simple rules: official apps only, no mystery links, everything important locked with 2FA. And the good thing is that Google reacts pretty fast to new threats like this one. So while it's good to stay alert, I wouldn't lose sleep over it – just tighten your settings a bit and go on with your day.
Unlimited plans for $15/mo at Mint!
$180
$360
$180 off (50%)
Mint Mobile is also offering an incredible bargain for those seeking unlimited data! The carrier's latest deal lets you grab any unlimited plan for just $15/mo, bringing the 12-month Unlimited plan to $180 instead of $360.
Izzy, a tech enthusiast and a key part of the PhoneArena team, specializes in delivering the latest mobile tech news and finding the best tech deals. Her interests extend to cybersecurity, phone design innovations, and camera capabilities. Outside her professional life, Izzy, a literature master's degree holder, enjoys reading, painting, and learning languages. She's also a personal growth advocate, believing in the power of experience and gratitude. Whether it's walking her Chihuahua or singing her heart out, Izzy embraces life with passion and curiosity.
A discussion is a place, where people can voice their opinion, no matter if it
is positive, neutral or negative. However, when posting, one must stay true to the topic, and not just share some
random thoughts, which are not directly related to the matter.
Things that are NOT allowed:
Off-topic talk - you must stick to the subject of discussion
Offensive, hate speech - if you want to say something, say it politely
Spam/Advertisements - these posts are deleted
Multiple accounts - one person can have only one account
Impersonations and offensive nicknames - these accounts get banned
To help keep our community safe and free from spam, we apply temporary limits to newly created accounts:
New accounts created within the last 24 hours may experience restrictions on how frequently they can
post or comment.
These limits are in place as a precaution and will automatically lift.
Moderation is done by humans. We try to be as objective as possible and moderate with zero bias. If you think a
post should be moderated - please, report it.
Have a question about the rules or why you have been moderated/limited/banned? Please,
contact us.
Things that are NOT allowed:
To help keep our community safe and free from spam, we apply temporary limits to newly created accounts: