Home News New Android Trojan Drains Bank Accounts and Spies on Chats
News

New Android Trojan Drains Bank Accounts and Spies on Chats

A dangerous new Android banking trojan called Sturnus is targeting mobile users by draining bank accounts and spying on encrypted chat applications. It spreads through fake apps or disguised APK files, tricking users into installing it on their devices.

Once installed, Sturnus requests high-level permissions, including Accessibility Services, which allow it to monitor screen content, simulate taps, and overlay fake login screens on legitimate banking or financial apps. This enables attackers to capture usernames, passwords, and other sensitive data.

Sturnus can also intercept messages from encrypted chat apps such as WhatsApp, Telegram, and Signal by capturing screen content after it has been decrypted, giving attackers access to private conversations.

The malware communicates with a remote server, sending stolen data and receiving commands. It can remotely control the device, hide its presence, prevent uninstallation, and erase evidence, making detection and removal very difficult.

Why Sturnus is Dangerous:

  • Combines banking theft, device takeover, and interception of encrypted communications.
  • Exploits legitimate Android features to remain undetected.
  • Can hide behind fake apps or updates, making unsuspecting users vulnerable.

How to Stay Safe:

  • Only install apps from official stores like Google Play.
  • Avoid sideloading APKs from unknown sources.
  • Carefully review app permissions, especially for Accessibility and overlay access.
  • Enable built-in security features and consider a reputable mobile security app.
  • Be cautious with links in messages that prompt app installations.

Sturnus demonstrates the increasing sophistication of mobile malware, showing that even encrypted communications and financial apps can be vulnerable if proper security measures are not followed

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles

News

International Crackdown Dismantles Nine Crime Networks Behind Massive Illegal Streaming Operations

International Crackdown Dismantles Nine Illegal Streaming Crime Networks European and international law...

News

AI-Built Ransomware Toolkit Automates EDR Evasion and Active Directory Reconnaissance

AI-Built Ransomware Toolkit Automates EDR Evasion and Active Directory Reconnaissance Cybersecurity researchers...

News

Fake ChatGPT Ads and Trusted AI Links Used to Deliver Password-Stealing Malware

Fake ChatGPT Desktop App Ads Spread Password-Stealing Malware Through AI-Linked Tricks Security...

News

Meta AI Exploited in Instagram Account Hijack Wave Affecting High-Value Users

Instagram Users Locked Out After Attackers Allegedly Exploit Meta AI Support System...