A New Android Banking Trojan Could Put Your Galaxy Phone at Risk

by | Nov 25, 2025 | News

SammyGuru has affiliate and sponsored partnerships, we may earn a commission.

Android’s security has improved a lot over the years, but researchers continue to uncover threats that show how creative attackers have become. The latest example is Sturnus, a new Android banking trojan that security teams describe as far more capable than the malware families we usually hear about.

Sturnus is apparently a new Android trojan that can break into banking apps

What makes Sturnus so dangerous is the way it behaves. Instead of trying to break encryption or intercept data in the background, it focuses on whatever appears directly on your screen. Once it gains Accessibility access, it can observe every interface element you interact with. That includes chats from WhatsApp, Telegram, and Signal after they have been decrypted and displayed on the device.

The malware also tries to fool users with realistic fake banking pages. These overlays are designed to sit on top of your real banking app and mimic its layout. So entering your login details feels normal. In reality, the credentials are sent to the attackers right away. In addition, Sturnus allows remote control through live screen feeds. This gives attackers the ability to type, tap, scroll, and even hide the display with a black screen.

Researchers believe Sturnus is not fully deployed yet. Most of the activity so far has appeared in Southern and Central Europe (via TheHackerNews). This suggests that the operators are testing region-specific overlays before launching a wider campaign. The trojan also checks for SIM changes, monitors installed apps, and blocks attempts to remove it by redirecting the user away from important settings.

Google has issued an official statement noting that no known samples of Sturnus are present on the Play Store and that Play Protect is already blocking the identified variants. That is helpful, but the simplest protections remain the same. Use trusted app sources, avoid granting Accessibility permissions to apps that should not need them. Most importantly, keep your phone updated so it stays ahead of emerging threats.

Google Preferred Source Badge for SammyGuru.com

Follow us on Google Discover & set us as a preferred source in Google News

Share this Post

___________________________

New Blog Posts

___________________________