Herodotus is an Android banking trojan and device-takeover malware family operated under a malware-as-a-service model. It has been observed in active campaigns targeting mobile users in Italy and Brazil, with overlay templates and targeting artifacts indicating broader interest in financial institutions in the United States, United Kingdom, Turkey, and Poland, as well as cryptocurrency services. The malware appears to be a distinct family that reuses some components and techniques associated with Brokewell rather than a direct evolution of it, and some reporting also notes feature overlap with Hook. Herodotus is assessed to still be under active development.
Herodotus is typically delivered through smishing-driven sideloading chains that use a dedicated dropper to install the payload and guide victims into enabling Android Accessibility Services. The dropper uses deceptive blocking overlays resembling loading or verification screens to conceal permission-granting activity, including attempts to work around newer Android restrictions affecting Accessibility abuse. Once enabled, Accessibility gives the malware extensive control over the device user interface.
The malware supports credential theft through targeted overlays displayed when victims open selected banking or cryptocurrency applications. It can collect installed application information from the device, receive targeting instructions from command infrastructure, and wait for specific apps to launch before presenting fraudulent login screens. Herodotus also steals SMS messages, including one-time passcodes used for two-factor authentication, logs on-screen content through Accessibility abuse, captures screen content, and has been reported to obtain lock-screen PINs or patterns. In addition to theft functions, it enables remote device takeover by performing taps, swipes, text entry, app interaction, and global Android actions, allowing operators to navigate apps, approve transactions, and conduct fraud in real time while hiding activity behind opaque or semi-transparent blocking overlays.
A defining feature of Herodotus is its attempt to mimic human behavior during remote fraud operations. It splits operator-supplied text into individual characters and inserts randomized delays between input events, generally in the range of hundreds to a few thousand milliseconds, to make automated interaction resemble human typing. This behavior is intended to reduce detection by anti-fraud systems and behavioral biometrics that rely on timing and machine-like interaction patterns. The malware communicates with its command infrastructure using MQTT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Nevertheless, the newly discovered malware, named Herodotus by its developers, does not seem to be a direct evolution of Brokewell, but a new threat with parts of Brokewell stitched together with original parts.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
First similarity is the obfuscation technique used in both malware families: encrypted strings are stored in native code and are decrypted once the corresponding Java class is used.
Overlay attack with fake pages displayed on top of the targeted applications requesting credentials
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a similar 2026 Android malware discovery; described only as a human-mimicking trojan.
Android banking trojan capable of mimicking human behavior to evade detection during remote device control.
Herodotus is an advanced Android banking trojan capable of mimicking human typing behaviors to evade detection and steal credentials.
Android banking trojan that evades detection by mimicking human behavior during remote-control operations on infected devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.