Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New Android Malware Herodotus Mimic Human Behaviour to Bypass Biometrics Detection

A sophisticated Android banking trojan named Herodotus has emerged on the mobile threat landscape, introducing groundbreaking techniques to evade detection systems.

A sophisticated Android banking trojan named Herodotus has emerged on the mobile threat landscape, introducing groundbreaking techniques to evade detection systems.

During routine monitoring of malicious distribution channels, the Mobile Threat Intelligence service discovered unknown malicious samples distributed alongside notorious malware variants like Hook and Octo.

Despite sharing distribution infrastructure, these samples revealed closer similarities to Brokewell, a malware family previously identified by ThreatFabric analysts.

However, Herodotus represents a distinct threat combining Brokewell elements with original code designed for advanced evasion.

Active campaigns have been observed targeting users in Italy and Brazil, with the malware offered as Malware-as-a-Service by threat actor K1R0 on underground forums.

Underground forum promoting Herodotus as Malware-as-a-Service (Source – Threat Fabric) ThreatFabric researchers identified that Herodotus follows modern banking trojan trends while introducing a capability distinguishing it from other device takeover malware—mimicking human behaviour during remote control sessions to bypass behavioural biometrics detection.

Major capabilities (Source – Threat Fabric) The malware operates through an infection chain beginning with side-loading, potentially involving SMiShing campaigns leading victims to malicious download links.

Once deployed, Herodotus leverages a custom dropper designed to bypass Android 13+ restrictions on Accessibility Services.

However, Herodotus represents a distinct threat combining Brokewell elements with original code designed for advanced evasion.
Henry Dalton · Thehackingpost

After installation, the dropper automatically launches the payload and opens Accessibility Service settings, prompting victims to enable the service while displaying a deceptive loading screen overlay that conceals granting dangerous permissions.

Following successful deployment, Herodotus collects installed application lists and transmits this data to its command-and-control server, which responds with targeted application lists and corresponding overlay links.

The trojan deploys fake credential-harvesting screens over legitimate banking applications, capturing login credentials and two-factor authentication codes through SMS interception.

What sets Herodotus apart is its approach to text input automation during device takeover attacks.

Traditional remote access trojans set text directly in input fields using the ACTION_SET_TEXT function or clipboard manipulation, delivering complete text strings instantaneously.

However, this machine-like behaviour creates suspicious patterns that behavioural anti-fraud systems detect as automated attack indicators.

Advertisement

Herodotus implements a novel technique where operator-specified text is split into individual characters, with each character set separately at randomized intervals.

Randomization of delay between set text events (Source – Threat Fabric) The malware introduces delays ranging from 300 to 3000 milliseconds between character input events, replicating natural human typing patterns.

This randomization attempts to evade rudimentary behavioural detection systems measuring input timing, though sophisticated systems modeling individual behaviour identify anomalies.

The malware panel includes a checkbox labeled “Delayed text” that operators toggle to enable human-like input simulation.

Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories