Brokewell is an Android banking trojan identified in 2024 and associated with campaigns targeting mobile users through deceptive application delivery and social-engineering lures. It is designed to compromise Android devices for financial fraud, primarily by abusing Accessibility Services to gain extensive control over the user interface and facilitate credential theft. Brokewell has been linked to malvertising activity on major social platforms and has also been referenced in later Android banking malware research as a code and capability influence on newer families such as Herodotus.
As a banking trojan, Brokewell is associated with overlay-based credential theft against financial applications and broader device-takeover style abuse enabled by Accessibility permissions. Reported overlap with Herodotus indicates Brokewell uses string obfuscation techniques involving encrypted strings and native-code-assisted decryption, and that at least some Brokewell components were reusable by other malware developers. This suggests an architecture oriented toward modularity and analysis resistance.
Brokewell targets Android devices and fits within the modern mobile banking-malware ecosystem focused on stealing banking credentials and enabling fraudulent transactions from infected phones. Its observed and inferred tradecraft places it among Android threats that rely on sideloaded or socially engineered installation flows, fake application themes, and permission abuse rather than exploitation of the operating system itself. Brokewell is notable both as an active Android banking threat and as a malware family whose code or techniques appear to have influenced subsequent mobile trojans.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In April, Cyble Research and Intelligence Labs (CRIL) released a detailed analysis of a newly surfaced Android Banking Trojan named Brokewell... Recently, we’ve discovered another new Android Banking Trojan, “Antidot,”
3 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Brokewell is an Android banking trojan discovered in April 2024. It shares some code modules with Herodotus, indicating possible reuse or adaptation by Herodotus developers.
Referenced as an Android banking trojan whose techniques/components (e.g., obfuscation approach and code references like "BRKWL_JAVA") appear to be borrowed by Herodotus; no additional capabilities described in this content.
Android banking malware family previously discovered by ThreatFabric. The report says Herodotus borrows code/techniques from it, including obfuscation patterns and a dynamic module with limited reused functionality.
An Android-focused stealer distributed via malvertising on Meta platforms (as described in the headline).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.