New Android Malware Mimics Human Behavior to Evade Detection
Essential information
- Published
- 28/10/2025 18:24
- Modified
- 28/10/2025 19:57
- Tags
- 2025-10-28 android banking trojan behavior mimicry brokewell credential-theft device takeover herodotus hook malware-as-a-service mqtt octo remote-control
- Related entities
- 1 observables, 1 intrusion sets (apt), 2 techniques (mitre), 8 others
Description
A new Android malware called Herodotus has been discovered, designed to perform device takeover while mimicking human behavior to bypass biometric detection. Active campaigns have been observed in Italy and Brazil. Herodotus is being offered as Malware-as-a-Service and shows links to the previously known Brokewell malware. It uses side-loading for distribution and employs various techniques to steal credentials and perform remote device control. A unique feature is its attempt to humanize remote actions by randomizing delays between text inputs. The malware targets financial organizations and crypto wallets, with potential for global expansion. Its development highlights the growing threat of Device-Takeover banking Trojans and the need for advanced, layered security approaches.