A newly discovered Android banking trojan named Herodotus is actively targeting devices running Android versions 9 through 16, employing sophisticated techniques to mimic human behavior and bypass security controls. The malware, offered as a Malware-as-a-Service (MaaS) by an operator known as “K1R0,” is designed to allow attackers to take full control of infected phones, enabling them to drain user accounts by evading biometric and behavioral detection systems. Security researchers have observed Herodotus using simulated human typing and interaction patterns to avoid automated detection, making it particularly effective against banking and financial applications.
Multiple cybersecurity sources have reported on the emergence and capabilities of Herodotus, highlighting its rapid adoption in the cybercriminal underground and its potential impact on mobile banking security. The malware has been featured in threat intelligence newsletters and technical blogs, with experts warning that its advanced evasion techniques represent a significant evolution in Android malware. Organizations and users are advised to remain vigilant, update their devices, and employ robust mobile security solutions to mitigate the risk posed by this new threat.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
MedImpact disclosed a security incident that took critical systems offline and caused delays in pharmacy claims payouts.
The Canadian Centre for Cyber Security and the RCMP reported multiple incidents in which hacktivists exploited internet-accessible industrial control systems.
Sweden's power grid operator confirmed it had been breached following a public claim by the Everest ransomware group, underscoring continued targeting of European critical infrastructure.
ThreatFabric reported a new Android banking trojan called Herodotus, described as malware-as-a-service sold by an actor using the alias "K1R0" and designed to mimic human behavior to evade bank defenses.
The Maryland Department of Information Technology launched a Vulnerability Disclosure Program to allow legal reporting of security flaws in the state's public-facing systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.