Security researchers have identified a new Android banking Trojan, dubbed Herodotus, which employs randomized input delays to evade behavioral detection systems. The malware, advertised on cybercrime forums, introduces pauses of up to three seconds when attackers use accessibility services to input credentials, mimicking the slower, inconsistent typing patterns of human users. This technique is designed to bypass security solutions that flag machine-like input speeds as suspicious, making it more difficult for traditional behavioral biometrics to detect fraudulent activity.
While Herodotus shares many features with other banking Trojans, its unique evasion method poses a challenge for financial institutions relying on input timing as a primary detection mechanism. Researchers from ThreatFabric note that more advanced behavioral biometrics, which model individual user behavior, may still be effective against this threat. The Trojan is poised for use in global campaigns, raising concerns about its potential impact on the finance and banking sector as cybercriminals continue to innovate in bypassing security controls.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
A later report stated that the Herodotus campaign expanded to include Ireland in addition to previously identified targets in the U.S., U.K., Turkey, and Poland. This marked a further geographic escalation of the malware's activity.
Analysis of Herodotus overlay pages and infrastructure showed targeting of financial institutions in the United States, United Kingdom, Poland, and Turkey, as well as cryptocurrency wallets and exchanges. This indicated the operators were preparing for wider international expansion beyond Italy and Brazil.
ThreatFabric publicly disclosed the new Herodotus Android banking trojan, highlighting its randomized input delays that mimic human typing to evade behavioral-biometrics and anti-fraud detection. The report also detailed capabilities including fake banking overlays, screen capture, opaque overlays, remote UI control, and theft of one-time passcodes.
Researchers observed Herodotus in active attacks against users in Italy and Brazil, delivered through smishing and sideloaded dropper apps masquerading as legitimate software. The malware abused Android Accessibility Services to enable device takeover, credential theft, and SMS interception.
ThreatFabric reported that the Android banking trojan Herodotus was being marketed as a malware-as-a-service offering by an author identified as K1R0, who reportedly described it as still under development on cybercrime forums. Researchers also linked it to shared components and techniques associated with Brokewell.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
8 references tracked. Mallory keeps watching after this page renders.
socradar.io
Open sourcesecurityonline.info
Open sourcethecyberthrone.in
Open sourcescworld.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.