logo

New Herodotus Android malware fakes human typing to avoid detection

ID: e00041e2-85a3-5a05-9d30-91235ec7f047

STIX ID: report--e00041e2-85a3-5a05-9d30-91235ec7f047

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-10-28

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Herodotus is a newly observed Android malware-as-a-service actively distributed via smishing against Italian and Brazilian users; it uses a dropper that requests Accessibility permissions, deploys overlays to mimic banking/crypto apps, intercepts SMS-based 2FA, captures screens, and provides an admin panel for operators. Notably, Herodotus implements a 'humanizer' that injects randomized typing delays (0.3–3s) to evade behavioral anti-fraud/detection systems, and Threat Fabric links its operators to the Brokewell ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.