New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices

Details of a new Android banking malware known as Sturnus, which permits credential theft and complete device takeover to carry out financial crime, have been revealed by cybersecurity researchers.

According to a research provided with The Hacker News by ThreatFabric, one of its main differentiators is its capacity to get beyond encrypted messaging. Sturnus can keep an eye on WhatsApp, Telegram, and Signal conversations by immediately recording content from the device screen after decryption.

Its capacity to stage overlay assaults by displaying phony login windows atop banking apps in order to obtain victims’ credentials is another noteworthy capability. The Dutch mobile security firm claims that Sturnus is privately run and is in the evaluation phase. The following is a list of artifacts that spread the financial malware:

  • Google Chrome (“com.klivkfbky.izaybebnx”)
  • Preemix Box (“com.uvxuthoq.noscjahae”)

With region-specific overlays, the malware is specifically made to target financial institutions in Southern and Central Europe read more about New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *