Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

New Android Trojan ‘Herodotus’ Outsmarts Anti-Fraud Systems by Typing Like a Human

Posted on October 28, 2025October 28, 2025 By CWS

Oct 28, 2025Ravie LakshmananMalware / Cell Safety
Cybersecurity researchers have disclosed particulars of a brand new Android banking trojan referred to as Herodotus that has been noticed in lively campaigns concentrating on Italy and Brazil to conduct gadget takeover (DTO) assaults.
“Herodotus is designed to carry out gadget takeover whereas making first makes an attempt to imitate human behaviour and bypass behaviour biometrics detection,” ThreatFabric stated in a report shared with The Hacker Information.
The Dutch safety firm stated the Trojan was first marketed in underground boards on September 7, 2025, as a part of the malware-as-a-service (MaaS) mannequin, touting its skill to run on units operating Android model 9 to 16.

It is assessed that whereas the malware will not be a direct evolution of one other banking malware often called Brokewell, it actually seems to have taken sure elements of it to place collectively the brand new pressure. This consists of similarities within the obfuscation method used, in addition to direct mentions of Brokewell in Herodotus (e.g., “BRKWL_JAVA”).

Herodotus can also be the most recent in an extended checklist of Android malware to abuse accessibility companies to understand its objectives. Distributed by way of dropper apps masquerading as Google Chrome (bundle identify “com.cd3.app”) by SMS phishing or different social engineering ploys, the bug leverages the accessibility function to work together with the display, serve opaque overlay screens to cover malicious exercise, and conduct credential theft by displaying bogus login screens atop monetary apps.
Moreover, it may possibly additionally steal two-factor authentication (2FA) codes despatched by way of SMS, intercept every part that is displayed on the display, grant itself additional permissions as required, seize the lockscreen PIN or sample, and set up distant APK recordsdata.

However the place the brand new malware stands out is in its skill to humanize fraud and evade timing-based detections. Particularly, this consists of an choice to introduce random delays when initiating distant actions akin to typing textual content on the gadget. This, ThreatFabric stated, is an try by the menace actors to make it look like the enter is being entered by an precise consumer.

“The delay specified is within the vary of 300 – 3000 milliseconds (0,3 – 3 seconds),” it defined. “Such a randomization of delay between textual content enter occasions does align with how a consumer would enter textual content. By consciously delaying the enter by random intervals, actors are seemingly attempting to keep away from being detected by behaviour-only anti-fraud options recognizing machine-like velocity of textual content enter.”
ThreatFabric stated it additionally obtained overlay pages utilized by Herodotus concentrating on monetary organisations within the U.S., Turkey, the U.Okay., and Poland, together with cryptocurrency wallets and exchanges, indicating that the operators try to actively increase their horizons.
“It’s below lively improvement, borrows strategies lengthy related to the Brokewell banking Trojan, and seems purpose-built to persist inside reside periods relatively than merely steal static credentials and give attention to account takeover,” the corporate famous.

The Hacker News Tags:Android, AntiFraud, Herodotus, Human, Outsmarts, Systems, Trojan, Typing

Post navigation

Previous Post: How Threat Intelligence Feeds Help Organizations Quickly Mitigate Malware Attacks
Next Post: XWiki RCE Vulnerability Actively Exploted In Wild To Deliver Coinminer

Related Posts

New Coyote Malware Variant Exploits Windows UI Automation to Steal Banking Credentials The Hacker News
Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries The Hacker News
New FileFix Method Emerges as a Threat Following 517% Rise in ClickFix Attacks The Hacker News
Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support The Hacker News
Claude AI Exploited to Operate 100+ Fake Political Personas in Global Influence Campaign The Hacker News
Microsoft to Block Unauthorized Scripts in Entra ID Logins with 2026 CSP Update The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure
  • LLMs are Accelerating the Ransomware Operations with Functional Tools and RaaS
  • From Open Source to OpenAI: The Evolution of Third-Party Risk
  • Link11 Identifies Five Cybersecurity Trends Shaping European Defense Strategies in 2026
  • Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure
  • LLMs are Accelerating the Ransomware Operations with Functional Tools and RaaS
  • From Open Source to OpenAI: The Evolution of Third-Party Risk
  • Link11 Identifies Five Cybersecurity Trends Shaping European Defense Strategies in 2026
  • Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark