Skip to content
Herodotus Android Trojan Mimics Human Behavior to Evade Detection

Herodotus Android Trojan Mimics Human Behavior to Evade Detection

First seen 23 Nov 2025, 03:35 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The Herodotus Android Trojan has emerged as a sophisticated banking malware that mimics human typing to evade detection by security systems. It is capable of stealing credentials, logging keystrokes, and intercepting SMS messages for two-factor authentication. This malware has been linked to attacks in Italy and Brazil and is offered as malware-as-a-service (MaaS).

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

More articles in this cluster (7)

Following this threat?

Track Anatsa and Signal in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed