Herodotus is an Android banking trojan and device-takeover malware family offered under a malware-as-a-service model to financially motivated operators. It has been linked through code reuse and tradecraft overlap to Brokewell, but is assessed as a distinct family rather than a direct evolution. Active campaigns have targeted users in Italy and Brazil, while recovered targeting material indicates broader interest in financial institutions in the United States, United Kingdom, Turkey, and Poland, as well as cryptocurrency services.
Herodotus is typically delivered through smishing and sideloaded dropper applications that socially engineer victims into installing the payload and granting Accessibility Services permissions. The dropper uses deceptive overlays resembling benign loading or verification screens to conceal permission-enablement steps, including attempts to work around newer Android restrictions affecting accessibility abuse.
Once installed, Herodotus abuses Android Accessibility Services to obtain extensive control over the device and support live fraud operations. Its capabilities include collecting installed application data, waiting for targeted apps to open, presenting credential-harvesting overlays, intercepting SMS messages including one-time passcodes, monitoring on-screen content, capturing lock-screen secrets such as PINs or patterns, and performing remote interface actions such as taps, swipes, text entry, app launches, and global navigation actions. It can also conceal attacker activity with blocking overlays during fraudulent sessions and has been reported to support installation of additional Android packages.
A defining feature of Herodotus is its attempt to mimic human behavior during remote-control fraud. It introduces randomized delays between input events, especially text entry, to make automated actions resemble human typing and reduce the effectiveness of timing-based behavioral and anti-fraud detections. This humanization capability distinguishes it from many earlier Android banking trojans focused primarily on overlays and accessibility abuse.
Herodotus communicates with command-and-control infrastructure using MQTT and appears to remain under active development. Its combination of accessibility-driven remote control, credential theft, SMS interception, overlay-based deception, and human-like interaction timing makes it a notable modern Android banking threat focused on real-time account takeover and transaction fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Nevertheless, the newly discovered malware, named Herodotus by its developers, does not seem to be a direct evolution of Brokewell, but a new threat with parts of Brokewell stitched together with original parts.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
First similarity is the obfuscation technique used in both malware families: encrypted strings are stored in native code and are decrypted once the corresponding Java class is used.
Overlay attack with fake pages displayed on top of the targeted applications requesting credentials
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan capable of mimicking human behavior to evade detection during remote device control.
Herodotus is an advanced Android banking trojan capable of mimicking human typing behaviors to evade detection and steal credentials.
Android banking trojan that evades detection by mimicking human behavior during remote-control operations on infected devices.
Android banking trojan strain reported to mimic human behavior to evade detection while enabling remote operation of an infected device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.