New Herodotus Android malware fakes human typing to avoid detection
ID: e00041e2-85a3-5a05-9d30-91235ec7f047
STIX ID: report--e00041e2-85a3-5a05-9d30-91235ec7f047
Feed Name: Bleeping Computer
Herodotus is a newly observed Android malware-as-a-service actively distributed via smishing against Italian and Brazilian users; it uses a dropper that requests Accessibility permissions, deploys overlays to mimic banking/crypto apps, intercepts SMS-based 2FA, captures screens, and provides an admin panel for operators. Notably, Herodotus implements a 'humanizer' that injects randomized typing delays (0.3–3s) to evade behavioral anti-fraud/detection systems, and Threat Fabric links its operators to the Brokewell ecosystem.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
