Sturnus Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
28
occurrences
First Seen
November 20, 2025
Last Seen
April 5, 2026

Sturnus is a malware family tracked across 10 threat clusters and 28 intelligence report mentions on ThreatCluster. First observed November 20, 2025; most recent activity April 5, 2026.

Related Threat Clusters

  • Critical Android Vulnerability Allows Quick Unlocking of Devices

    A newly discovered vulnerability, CVE-2026-20435, affects certain Android phones using MediaTek processors, allowing attackers to unlock devices and extract sensitive information in under a minute. Researchers estimate…

    5 articles · Updated April 5, 2026
  • New Android Malware Targets Banking Information and Device Control

    A new malware named Sturnus has been identified, capable of hijacking Android devices and stealing sensitive information, including banking details and chat messages. Additionally, a malware-as-a-service platform called…

    5 articles · Updated November 26, 2025
  • Critical Windows Graphics Vulnerabilities Enable Remote Code Execution

    Multiple vulnerabilities in the Windows Graphics Device Interface (GDI) have been identified, allowing remote code execution (RCE) and data leaks. Discovered by Check Point Research, these flaws involve malformed…

    5 articles · Updated November 21, 2025
  • New Android Malware 'Sturnus' Steals Banking Credentials and Encrypted Chats

    Cybersecurity researchers have identified a new Android banking trojan named Sturnus, capable of stealing banking credentials and accessing encrypted messages from apps like WhatsApp, Telegram, and Signal. The malware…

    48 articles · Updated December 2, 2025
  • Surge in Android Malware: Albiriox and Sturnus Target User Accounts

    In 2025, Android users are facing a significant increase in malware threats, specifically from strains named Albiriox and Sturnus. These malware types are capable of taking over personal accounts, manipulating banking…

    2 articles · Updated December 30, 2025
  • WhatsApp Security Flaw Exposes 3.5 Billion Phone Numbers

    A security flaw in WhatsApp allowed researchers to extract phone numbers of 3.5 billion users. The exploit involved systematically checking numbers through the app's discovery feature, revealing profile photos for 57%…

    56 articles · Updated November 18, 2025
  • Sturnus Android Trojan Compromises Encrypted Messaging Apps

    The Sturnus Android malware has been identified as a banking trojan that extracts communications from secure messaging applications, including WhatsApp, Telegram, and Signal. Users of these platforms are at risk as the…

    9 articles · Updated November 20, 2025
  • Herodotus Android Trojan Mimics Human Behavior to Evade Detection

    The Herodotus Android Trojan has emerged as a sophisticated banking malware that mimics human typing to evade detection by security systems. It is capable of stealing credentials, logging keystrokes, and intercepting…

    7 articles · Updated November 7, 2025
  • New Android Trojan Sturnus Steals Credentials and Controls Devices

    The Android banking trojan Sturnus has been identified, capable of stealing user credentials, reading encrypted messages, and taking control of devices. This malware poses a significant risk to users' financial security…

    2 articles · Updated December 25, 2025
  • Ex-Google Engineer Convicted for Stealing AI Secrets for China

    A former Google engineer has been found guilty of stealing proprietary AI technology to benefit China. The case highlights the ongoing concerns regarding intellectual property theft and espionage in the tech industry.…

    13 articles · Updated January 31, 2026

Recent Intelligence Reports

  • Android flaw lets hackers unlock phones in under a minute — Foxnews · April 5, 2026
  • 2025 Android Malware Surge: Albiriox and Sturnus Enable Account Takeovers — Webpronews · December 30, 2025
  • New malware can read your chats and steal your money — Yahoo · December 25, 2025
  • Password-stealing virus detected on Android phones - Zamin.uz, 29.11.2025 — Zamin.Uz · November 29, 2025
  • New Android trojan 'Sturnus' can read encrypted chats and drain bank accounts — Moneycontrol · November 29, 2025
  • A new Android trojan could bypass WhatsApp, Signal and Telegram encryption steal your money — Msn · November 27, 2025
  • New Android malware that can hijack your phone and bank accounts found — Currently.Att.Yahoo · November 26, 2025
  • New Android Banking Trojan “Sturnus” Can Read Encrypted Chats on WhatsApp, Telegram ... — Cxodigitalpulse · November 26, 2025

CVSS v3.1 Breakdown