Thehackernews
Herodotus: Advanced Android Trojan Mimics Human Behavior to Steal Banking Credentials
First seen 2 Nov 2025, 16:14 UTC
•



+1
•71% similarity
•26.6
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The Herodotus Trojan is a new Android banking malware identified by ThreatFabric that mimics human typing patterns to evade detection by anti-fraud systems. It employs random delays between keystrokes and can intercept SMS messages to capture two-factor authentication codes. This malware has been reported in device takeover attacks in Italy and Brazil, and is offered as malware-as-a-service (MaaS).
ThreatCluster AI
How this analysis works