By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: New Android Trojan ‘Herodotus’ Outsmarts Anti-Fraud Systems by Typing Like a Human
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > New Android Trojan ‘Herodotus’ Outsmarts Anti-Fraud Systems by Typing Like a Human
Tech News

New Android Trojan ‘Herodotus’ Outsmarts Anti-Fraud Systems by Typing Like a Human

By Viral Trending Content 5 Min Read
Share
SHARE

Oct 28, 2025Ravie LakshmananMalware / Mobile Security

Android Trojan

Cybersecurity researchers have disclosed details of a new Android banking trojan called Herodotus that has been observed in active campaigns targeting Italy and Brazil to conduct device takeover (DTO) attacks.

“Herodotus is designed to perform device takeover while making first attempts to mimic human behaviour and bypass behaviour biometrics detection,” ThreatFabric said in a report shared with The Hacker News.

The Dutch security company said the Trojan was first advertised in underground forums on September 7, 2025, as part of the malware-as-a-service (MaaS) model, touting its ability to run on devices running Android version 9 to 16.

DFIR Retainer Services

It’s assessed that while the malware is not a direct evolution of another banking malware known as Brokewell, it certainly appears to have taken certain parts of it to put together the new strain. This includes similarities in the obfuscation technique used, as well as direct mentions of Brokewell in Herodotus (e.g., “BRKWL_JAVA”).

Herodotus is also the latest in a long list of Android malware to abuse accessibility services to realize its goals. Distributed via dropper apps masquerading as Google Chrome (package name “com.cd3.app”) through SMS phishing or other social engineering ploys, the malicious program leverages the accessibility feature to interact with the screen, serve opaque overlay screens to hide malicious activity, and conduct credential theft by displaying bogus login screens atop financial apps.

Additionally, it can also steal two-factor authentication (2FA) codes sent via SMS, intercept everything that’s displayed on the screen, grant itself extra permissions as required, grab the lockscreen PIN or pattern, and install remote APK files.

But where the new malware stands out is in its ability to humanize fraud and evade timing-based detections. Specifically, this includes an option to introduce random delays when initiating remote actions such as typing text on the device. This, ThreatFabric said, is an attempt by the threat actors to make it seem like the input is being entered by an actual user.

“The delay specified is in the range of 300 – 3000 milliseconds (0,3 – 3 seconds),” it explained. “Such a randomization of delay between text input events does align with how a user would input text. By consciously delaying the input by random intervals, actors are likely trying to avoid being detected by behaviour-only anti-fraud solutions spotting machine-like speed of text input.”

CIS Build Kits

ThreatFabric said it also obtained overlay pages used by Herodotus targeting financial organisations in the U.S., Turkey, the U.K., and Poland, along with cryptocurrency wallets and exchanges, indicating that the operators are attempting to actively expand their horizons.

“It is under active development, borrows techniques long associated with the Brokewell banking Trojan, and appears purpose-built to persist inside live sessions rather than simply steal static credentials and focus on account takeover,” the company noted.

The findings comes as CYFIRMA detailed an advanced Android malware named GhostGrab that’s capable of systematically harvesting banking credentials while covertly mining Monero cryptocurrency on infected devices, creating a “dual-revenue stream” for the threat actors. The campaign appears to be targeting Android users in India.

The dropper app, which impersonates a financial app, requests for the REQUEST_INSTALL_PACKAGES permission to facilitate in-app installation of additional APKs without using the Google Play Store. The main payload installed on the device requests a high-risk set of permissions to enable call forwarding, steal SMS data, and serve fake WebView pages that mimic a KYC form to collect personal information, including card details, four-digit ATM PIN, and government ID such as Aadhaar number.

“GhostGrab functions as a hybrid threat, combining covert cryptocurrency mining operations with comprehensive data exfiltration capabilities,” the company said. “It is engineered to systematically harvest sensitive financial information, including banking credentials, debit card details, and one-time passwords (OTPs) via SMS interception.”

You Might Also Like

20% Off Brooks Promo Code & Deals for November 2025

Nexperia confident of ‘de-escalation’ but can’t guarantee Chinese chips quality

Bag A Sky Glass Air 4K TV For Just £3pm In Huge Early Black Friday Sale

DJI Zenmuse L3 LiDAR Specs & Performance : 950M Range & Dual 100 MP Cameras

Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data

TAGGED: Android, banking Trojan, Cryptocurrency Theft, Cyber Security, Cybersecurity, Internet, Malware, Malware-as-a-Service, mobile security, social engineering, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article Serbia’s EU bid: Necessity-driven joint ambition facing foreign policy hurdles
Next Article The deep-tech founder growing the thermoelectric materials sector
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

20% Off Brooks Promo Code & Deals for November 2025
Tech News
Seahawks WR Rashid Shaheed Eyes Extension After Trade: 'I'm Here to Stay'
Sports
Bitcoin shaken by long-term holders dumping $45 billion
Business
Rain launches its decentralized prediction markets protocol, where anyone can create their own market – private or public
Crypto
Bitcoin Finally Recovers — Why Bitcoin Hyper Becomes One of the Best Crypto to Buy
Crypto
Nexperia confident of ‘de-escalation’ but can’t guarantee Chinese chips quality
Tech News
Is France going to link its digital ID to your social media accounts?
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

20% Off Brooks Promo Code & Deals for November 2025

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
20% Off Brooks Promo Code & Deals for November 2025
November 6, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?