Spyware Bypass Signal/Telegram/WhatsApp Encryption to Read Messages

Spyware Bypass Signal/Telegram/WhatsApp Encryption to Read Messages
Spyware Bypass Signal/Telegram/WhatsApp Encryption to Read Messages

By: Shane Barney, Chief Information Security Officer (CISO), Keeper Security 

"Sturnus is yet another dangerous escalation in mobile fraud, with the Android banking trojan not only stealing credentials and enabling full device takeover, but also reading end-to-end encrypted chats by capturing content after it is decrypted on the device. 

That’s an important distinction because it means that this is not a cryptographic failure of Signal, WhatsApp or Telegram, but an on-device compromise. In practice, the malware abuses powerful Android permissions to spy on the screen, capture messages and execute transactions in real time while suppressing warnings that could signal fraud. Early activity suggests operators are testing Sturnus in targeted campaigns, but the components it combines are already well-proven, meaning rapid scaling is possible once distribution methods improve. 

Organisational and security leaders should act with urgency and treat mobile endpoints as high-value assets. This means enforcing enterprise mobility and app-install controls, requiring device attestation and strong endpoint detection for Android, and blocking accessibility and remote-control permissions unless they are explicitly needed and vetted. Organisations should also move official communications and regulated workflows off consumer messaging apps and adopt secure, enterprise-governed communications. 

Businesses should also assume compromise and limit what an attacker can access even if a device is compromised. Strong privileged access management, least-privilege policies, regular credential rotation, segmented networks and adaptive multi-factor authentication can prevent a single compromised handset from becoming an entry-point to high-value systems. User education also remains critical – avoid sideloading apps, review permissions and scrutinise unexpected links or prompts. Detection rules and mobile-focused threat-intelligence must be kept current to match the pace of these evolving tactics. 

Sturnus is a stark reminder that end-to-end encryption protects data in transit, not a compromised device. Effective security must be holistic, combining hardened endpoints, locking down access pathways and defenses built for an environment where attackers will increasingly target the human and the handset."