By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: New Android banking trojan is draining accounts and snooping on encrypted chats — how to stay safe
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > New Android banking trojan is draining accounts and snooping on encrypted chats — how to stay safe
News

New Android banking trojan is draining accounts and snooping on encrypted chats — how to stay safe

News Room
Last updated: 2025/11/26 at 4:43 PM
News Room Published 26 November 2025
Share
New Android banking trojan is draining accounts and snooping on encrypted chats — how to stay safe
SHARE

Earlier this year, Google announced plans to make sideloading apps significantly harder to do on the best Android phones. However, many Android owners did not welcome this controversial move.

Now though, fans of sideloading apps might want to reconsider thanks to a new malware strain that can bypass encrypted chats in apps like WhatsApp and Signal and targets financial apps. This new banking trojan, dubbed Sturnus, originates in malicious APKs.

Researchers from MTI Security first discovered Sturnus (via ThreatFabric) and noted it can bypass some security measures by gaining high-level access to the contents of your screen which allows it to view those encrypted chats you thought were safe from prying eyes.


Best picks for you

The malware can also recreate banking screens using overlay attacks to phish your login credentials and launch device-level attacks. This means that cybercriminals could remotely control take over your device. Likewise, it can also create fake Android updates to hide its activity.

How Sturnus works

According to ThreatFabric, Sturnus has been used in attacks in both Southern and Central Europe, which the cybersecurity firm claim suggests preparations for a “broader campaign.”

The malware apparently uses a “chaotic mix” of plaintext, RSA and AES communications that it switches unpredictably between while sending out simple and complex messages.

According to the researchers, they suspect the malware may be transmitted via rogue attachments in messaging apps. It propagates by disguising itself as fake versions of Google Chrome and other popular apps. From there, it then gains Admin rights on the phone which enables the malware to prevent itself from being uninstalled and locking the device.

Get instant access to breaking news, the hottest reviews, great deals and helpful tips.

(Image credit: ThreatFabric)

While Sturnus is designed to get around encrypted conversations, it sends stolen data back to hacker-controlled servers using an encrypted 256-bit AES key.

Sturnus appears to be in its “pre-development” stages, but the researches say it could be used as for advanced attacks right now. Unfortunately, given how dangerous it ism the only way to prevent it at the moment is to avoid downloading APK files online to sideload Android apps.

A Google spokesperson told Android Authority that according to their detection programs, there are no malicious apps in the which Play Store contain Sturnus.


Don’t miss these

How to stay safe from Android malware


Digitally created image of a ghostly digital lock being touched by a human hand.

(Image credit: sdecoret/Shutterstock)

First of all, to avoid falling victim to Sturnus and other Android malware strains, you shouldn’t sideload apps on your devices.

Doing so puts you at serious risk of being plagued by malware, adware, spyware and other threats. Apps found in unofficial third-party app stores or downloaded as APK files don’t go through the same rigorous security checks as they would on the Google Play Store or other first-party stores like the Samsung Galaxy Store.

Beyond not sideloading apps, you also want to make sure that Google Play Protect is enabled on your Android smartphone or tablet. This pre-installed security app scans all of your existing apps and any new ones you download for malware and other threats. However, you should also consider running one of the best Android antivirus apps alongside it for extra protection.

Malicious apps are one the easiest ways for hackers and other cybercriminals to establish a foothold on your devices. So it’s up to you to carefully vet every app you install. Sticking to official, first-party app stores and limiting the number of apps installed on your phone should keep you relatively safe from Sturnus and other malware strains too.



Google News

Follow Tom’s Guide on Google News and add us as a preferred source to get our up-to-date news, analysis, and reviews in your feeds.


More from Tom’s Guide

Today’s identity theft protection deals

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Comings and goings: Software exec Jo Lambert elected chair of NPR board, CPB SVP departs … Comings and goings: Software exec Jo Lambert elected chair of NPR board, CPB SVP departs …
Next Article Today's NYT Connections Hints, Answers for Nov. 27 #900 Today's NYT Connections Hints, Answers for Nov. 27 #900
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Your Galaxy Watch 6 just got a major upgrade in the US with One UI 8 Watch
Your Galaxy Watch 6 just got a major upgrade in the US with One UI 8 Watch
News
A 600 kilometer quantum network is one of its great strategic bets
A 600 kilometer quantum network is one of its great strategic bets
Mobile
Scientists capture the crackling sounds of what they believe is lightning on Mars
News
Best Rowing Machines of 2025 – CNET
Best Rowing Machines of 2025 – CNET
News

You Might also Like

Your Galaxy Watch 6 just got a major upgrade in the US with One UI 8 Watch
News

Your Galaxy Watch 6 just got a major upgrade in the US with One UI 8 Watch

2 Min Read

Scientists capture the crackling sounds of what they believe is lightning on Mars

5 Min Read
Best Rowing Machines of 2025 – CNET
News

Best Rowing Machines of 2025 – CNET

5 Min Read
Paxos acquires crypto wallet startup Fordefi for 0M+ –  News
News

Paxos acquires crypto wallet startup Fordefi for $100M+ – News

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?