Researchers studying cybersecurity have revealed information on Herodotus, a new Android banking malware that has been seen in active efforts to carry out device takeover (DTO) assaults against Brazil and Italy.
According to a study provided to The Hacker News by ThreatFabric, Herodotus is made to take control of devices while initially attempting to imitate human behavior and evade behavior biometric detection.
According to the Dutch security firm, on September 7, 2025, the Trojan was first promoted in underground forums under the malware-as-a-service (MaaS) paradigm, claiming to be compatible with Android 9–16 devices.
Although the malware does not directly evolve from previous financial malware called Brokewell, it does seem to have borrowed some of its components to create the new strain. This contains direct references to Brokewell in Herodotus (e.g., “BRKWL_JAVA”) and parallels in the obfuscation tactic employed read more about New Android Trojan ‘Herodotus’ Outsmarts Anti-Fraud Systems by Typing Like a Human.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
