Skip to content
Sturnus Android Trojan Compromises Encrypted Messaging Apps

Sturnus Android Trojan Compromises Encrypted Messaging Apps

First seen 20 Nov 2025, 14:17 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The Sturnus Android malware has been identified as a banking trojan that extracts communications from secure messaging applications, including WhatsApp, Telegram, and Signal. Users of these platforms are at risk as the malware can capture encrypted chats and hijack devices, potentially leading to significant privacy breaches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 184d ago How this analysis works

More articles in this cluster (9)

Following this threat?

Track Sturnus and Signal in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed