Sturnus Android Malware Directly Captures Screen, Bypassing E2EE

A new strain of insidious Android malware has been discovered that can “bypass encrypted messaging” by capturing content directly from the screen after decryption.


This is a companion discussion topic for the original entry at https://www.privacyguides.org/news/2025/11/20/sturnus-android-malware-can-bypass-encrypted-messaging-capable-of-full-device-takeover

And this is why I still consider that using GOS with:

  • regular “safe apps” on the main account
  • having a 2nd profile for bank/important apps
  • having a 3rd profile for all the trash apps like Gyms apps etc

is still the way to go. :sweat_smile:
Nothing beats clean sharp separation with no cross contamination.

PS: I do assume that I’m right on thinking that this malware cannot reach out from a profile to another. Otherwise forget what I wrote. :see_no_evil_monkey: