{"id":306296,"date":"2025-11-25T17:01:09","date_gmt":"2025-11-25T17:01:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/306296\/"},"modified":"2025-11-25T17:01:09","modified_gmt":"2025-11-25T17:01:09","slug":"hackers-bypass-signal-telegram-and-whatsapp-encryption-to-read-messages-2","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/306296\/","title":{"rendered":"Hackers Bypass Signal, Telegram And WhatsApp Encryption To Read Messages"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2025\/11\/1763996052_343_0x0.jpg\" alt=\"A finger hovers above the Telegram, Signal and WhatsApp smartphone app icons.\" data-height=\"1638\" data-width=\"2458\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Beware the Sturnus malware attacks that bypass instant messenger encryption to read your texts.<\/p>\n<p>Photothek via Getty Images<\/p>\n<p>Updated November 25 with a new warning from America\u2019s Cyber Defense Agency, CISA, regarding how spyware is targeting users of instant messaging applications, as well as further comments from malware experts regarding the Sturnus threat from hackers impacting all secure messenger users.<\/p>\n<p>Nobody wants their secrets to leak, whether that is the <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/18\/department-of-war-leaks-secrets-us-government-accountability-office-says\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/18\/department-of-war-leaks-secrets-us-government-accountability-office-says\/\" target=\"_self\" aria-label=\"Department of War\" rel=\"nofollow noopener\">Department of War<\/a>, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/18\/ftse-100-credentials-stolen-nearly-half-a-million-now-for-sale\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/18\/ftse-100-credentials-stolen-nearly-half-a-million-now-for-sale\/\" target=\"_self\" aria-label=\"FTSE 100 companies\" rel=\"nofollow noopener\">FTSE 100 companies<\/a>, or your average <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/11\/google-issues-critical-vpn-threat-warning-for-billions-of-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/11\/google-issues-critical-vpn-threat-warning-for-billions-of-users\/\" target=\"_self\" aria-label=\"consumer VPN\" rel=\"nofollow noopener\">consumer VPN<\/a> user. One place where many secrets exist is within the encrypted instant messages we send via apps such as Signal, Telegram and WhatsApp. So, what if I were to tell you that a new threat has been identified, targeting Android smartphone users, that effectively bypasses the secure encryption that protects the privacy of your messages, and captures them for cybercriminal hackers to read? Welcome to the distinctly dangerous world of the Sturnus trojan. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-9\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/25\/amazon-issues-attack-warning-for-300-million-customers\/?ss=cybersecurity\" target=\"_blank\" aria-label=\"Amazon Issues New Attack Warning For 300 Million Customers\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/25\/amazon-issues-attack-warning-for-300-million-customers\/?ss=cybersecurity\" rel=\"nofollow noopener\">ForbesAmazon Issues New Attack Warning For 300 Million CustomersBy Davey Winder<\/a>These Hackers Can Read Your \u2018Private\u2019 Instant Messages<\/p>\n<p>Security researchers at threat intelligence outfit ThreatFabric have confirmed that they have observed a new and dangerous piece of Android malware, a banking trojan that goes beyond the normal boundaries of such malicious software. Not only can Sturnus, which the ThreatFabric analysis said is \u201ccurrently in a development or limited testing phase,\u201d provide hackers with the ability to gain full device control and harvest banking credentials, but also, and here\u2019s the killer blow, it can \u201cbypass encrypted messaging\u201d according to the in-depth <a class=\"color-link\" href=\"https:\/\/www.threatfabric.com\/blogs\/sturnus-banking-trojan-bypassing-whatsapp-telegram-and-signal\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.threatfabric.com\/blogs\/sturnus-banking-trojan-bypassing-whatsapp-telegram-and-signal\" aria-label=\"technical report\">technical report<\/a>.<\/p>\n<p>I\u2019m a user of all three of these instant messaging apps, for different use-cases, and rely upon Signal and WhatsApp encryption for some of them. The good news is that this has not been broken, the attackers have not found a way to read your encrypted messages. What they have done, however, is put together a complex technical process that, ultimately, does something very simple indeed: it reads your messages after you\u2019ve decrypted them and they are displayed on the smartphone screen. This harks back to a warning that I used to give people all the time when secure messengers made a big play on the fact that screenshots could be disabled on time-limited, one-hit and done, messages, so the recipient couldn\u2019t take a copy and share it around. They could if they took a photo of the screen with another device. <\/p>\n<p>It\u2019s also a good time to remind people not to download apps from untrusted sources, even if they appear to be a legitimate Google Chrome update, which seems to be one of the distribution methods for the Sturnus malware.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-8\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/25\/internet-domain-name-registration-attacks-confirmed---what-to-know\/\" target=\"_blank\" aria-label=\"Internet Domain Name Registration Attacks Confirmed \u2014 What To Know\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/25\/internet-domain-name-registration-attacks-confirmed---what-to-know\/\" rel=\"nofollow noopener\">ForbesInternet Domain Name Registration Attacks Confirmed \u2014 What To KnowBy Davey Winder<\/a>Security Expert Reveals Threat From Hackers Posed To All Organizations By The Sturnus Trojan <\/p>\n<p>\u201cSturnus poses a different kind of threat compared to other Android malware due to its ability to use a mix of plaintext, RSA, and AES-encrypted communication with the C2 server it responds to,\u201d is the warning that Aditya Sood, vice president of security engineering and AI strategy at Aryaka, conveyed to me in an email concerning the dangers facing all organizations, rather than just consumers, by this latest trojan malware development. <\/p>\n<p>There\u2019s a lot of technology jargon to unravel there, so let me get that out of the way before going any further. RSA refers to the Rivest, Shamir, and Adleman family of public-key cryptosystems that is still used for secure data transmission, despite being one of the oldest. AES, meanwhile, is the Advanced Encryption Standard, another encryption specification, this time established by the National Institute of Standards and Technology in 2001. The simplest of the three to explain is the C2 server reference, which is the command and control (two C\u2019s, get it?) server involved, in this case Matrix Push C2.<\/p>\n<p>\u201cThe combination of these three,\u201d Sood continued, \u201callows Sturnus to blend more easily into normal network patterns, while also hiding commands and stolen data from defense systems.\u201d And it is this particularly advanced kind of evasion, and resilience, that enables the malware to disrupt signature-based detection and impede reverse-engineering efforts. This, Sood, warned, makes it much \u201charder to inspect Sturnus\u2019 network traffic or recover the contents that it steals.\u201d<\/p>\n<p>Which brings us to the \u2018all organizations\u2019 warning: \u201cThe ability to steal messages from end-to-end encrypted platforms like Signal could spell serious problems for organizations,\u201d Sood concluded, \u201cas those applications are used across several industries to secure sensitive or confidential information.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-10\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/25\/do-not-download-these-windows-security-updates-experts-warn\/\" target=\"_blank\" aria-label=\"Do Not Download These Windows Security Updates, Experts Warn\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/25\/do-not-download-these-windows-security-updates-experts-warn\/\" rel=\"nofollow noopener\">ForbesDo Not Download These Windows Security Updates, Experts WarnBy Davey Winder<\/a>Hackers Can Read Everything That Appears On Your Smartphone Screen<\/p>\n<p>\u201cBecause it relies on Accessibility Service logging rather than network interception,\u201d the report said, \u201cthe malware can read everything that appears on screen\u2014including contacts, full conversation threads, and the content of incoming and outgoing messages\u2014in real time.\u201d It is this capability that makes Sturnus particularly dangerous, in the view of the researchers and me, as it side-steps the protection that end-to-end encryption provides. As I\u2019ve often stated, a compromised device is not secure, and nor is anything on it. \u201cThe user sees a secure interface, but from the moment the device is compromised,\u201d the researchers confirmed, \u201cevery sensitive exchange becomes visible to the operator, with no cryptographic protection left to rely on.\u201d<\/p>\n<p>You can read more about instant messenger security here:<\/p>\n<p><a class=\"color-link\" href=\"https:\/\/support.signal.org\/hc\/en-us\/categories\/360000674811-Security\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/support.signal.org\/hc\/en-us\/categories\/360000674811-Security\" aria-label=\"Signal\">Signal<\/a> <\/p>\n<p><a class=\"color-link\" href=\"https:\/\/telegram.org\/faq#security\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/telegram.org\/faq#security\" aria-label=\"Telegram\">Telegram<\/a> <\/p>\n<p><a class=\"color-link\" href=\"https:\/\/faq.whatsapp.com\/1095301557782068\/?cms\\_platform=android\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/faq.whatsapp.com\/1095301557782068\/?cms\\_platform=android\" aria-label=\"WhatsApp\">WhatsApp<\/a><\/p>\n<p>So, if you don\u2019t want hackers reading your private stuff, ensure it stays that way by keeping Google\u2019s Play Protect activated, avoiding unauthorized app stores and not giving permission for accessibility controls to be enabled under less there\u2019s a very good reason and you are 101% sure it is safe to do so.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-7\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/18\/meta-pays-whatsapp-hackers-4-million---what-you-need-to-know\/\" target=\"_blank\" aria-label=\"WhatsApp And Meta Pay Hackers $4 Million \u2014 What To Know\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/11\/18\/meta-pays-whatsapp-hackers-4-million---what-you-need-to-know\/\" rel=\"nofollow noopener\">ForbesWhatsApp And Meta Pay Hackers $4 Million \u2014 What To KnowBy Davey Winder<\/a>Cybersecurity And Infrastructure Security Agency Publishes New Warning As Hackers Target Messenger Apps With Spyware<\/p>\n<p>An alert published by the Cybersecurity And Infrastructure Security Agency, known as CISA or as it styles itself \u201cAmerica\u2019s Cyber Defense Agency,\u201d has confirmed the risk faced by users of messaging applications from cyber threat actors employing commercial spyware applications. \u201cThese cyber actors use sophisticated targeting and social engineering techniques to deliver spyware and gain unauthorized access to a victim\u2019s messaging app,\u201d the <a class=\"color-link\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/11\/24\/spyware-allows-cyber-threat-actors-target-users-messaging-applications\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/11\/24\/spyware-allows-cyber-threat-actors-target-users-messaging-applications\" aria-label=\"CISA cybersecurity advisory\">CISA cybersecurity advisory<\/a> stated, \u201cfacilitating the deployment of additional malicious payloads that can further compromise the victim\u2019s mobile device.\u201d<\/p>\n<p>The tactics employed by even the most advanced hackers looking to target potential victims with the most sophisticated spyware malware are, it has to be said, remarkably familiar to anyone who has read any news report about phishing and spyware attacks over the years. CISA highlighted the following, for example:<\/p>\n<p>Phishing and malicious <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/22\/this-password-hack-jumps-from-laptop-to-smartphone---attacks-underway\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/22\/this-password-hack-jumps-from-laptop-to-smartphone---attacks-underway\/\" target=\"_self\" aria-label=\"device-linking QR codes\" rel=\"nofollow noopener\">device-linking QR codes <\/a>to compromise victim accounts and link them to actor-controlled devices.<a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/01\/whatsapp-hackers-offered-1-million-for-new-0-click-exploit\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/01\/whatsapp-hackers-offered-1-million-for-new-0-click-exploit\/\" target=\"_self\" aria-label=\"Zero-click exploits\" rel=\"nofollow noopener\">Zero-click exploits<\/a>, which require no direct action from the device user.Impersonation of messaging app platforms, such as Signal and WhatsApp.<\/p>\n<p>Although the vast majority of ordinary users will not be targeted by espionage attackers, nation-state hackers and the like, who tend to focus their valuable time, and valuable spyware assets, on high-profile victims such as politicians, journalists, activists, and the military, the mitigation advice is worth reading as it applies to everyone.<\/p>\n<p>Advice such as remaining vigilant against hackers using social engineering methods, such as claiming an account has been compromised, which requires the recipient to log in to confirm their identity and regain control over their account. Avoiding the scanning of any group-invitation links or QR codes that come from unverified sources. Talking of which, CISA recommends verifying \u201cthe authenticity of group invitations by contacting the group creator or administrator through separate communication channels.\u201d<\/p>\n<p>Then there\u2019s the fine advice to be highly suspicious of all and any unexpected security alert messages, even when they appear to be generated by the application itself, and \u201cespecially if the message requests authentication\u201d by way of PIN code or one-time authentication code. Finally, I\u2019d recommend following the CISA know-how when it says that you should limit linking of devices to only those that are absolutely necessary, which should go without saying, but hey. <\/p>\n","protected":false},"excerpt":{"rendered":"Beware the Sturnus malware attacks that bypass instant messenger encryption to read your texts. Photothek via Getty Images&hellip;\n","protected":false},"author":2,"featured_media":303931,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[1121,136409,49,48,7474,20241,136408,136405,61,42876,136407,3632,136406],"class_list":["post-306296","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-android","tag-android-message-hack","tag-ca","tag-canada","tag-malware","tag-signal","tag-signal-hack","tag-sturnus","tag-technology","tag-telegram","tag-telegram-hack","tag-whatsapp","tag-whatsapp-hack"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/306296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=306296"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/306296\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/303931"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=306296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=306296"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=306296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}