Cybersecurity News Hub
No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
No Result
View All Result
Cybersecurity News Hub
No Result
View All Result
Home Cyber Crime

New Android malware mimics human typing to evade detection, steal money

Cyberinchief by Cyberinchief
October 28, 2025
Reading Time: 2 mins read
0
New Android malware mimics human typing to evade detection, steal money



RELATED POSTS

Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London

AI Expert: We Have 2 Years Before Everything Changes! We Need To Start Protesting! — Tristan Harris – Lifeboat News: The Blog

Russian police bust bank-account hacking gang that used NFCGate-based malware

Researchers have discovered a new Android banking malware called Herodotus that evades detection by mimicking human behavior when remotely controlling infected devices.

The malware — developed by a little-known hacker who goes by the name K1R0 — can take full control of a victim’s phone to steal money from banking apps and online accounts. According to a report released Tuesday by Dutch cybersecurity firm ThreatFabric, the developer has advertised plans to sell the tool as a service on underground forums.

Researchers said they have observed active campaigns using the malware in Italy and Brazil. In Italy, Herodotus disguised itself as an app called Banca Sicura (“Safe Bank”), while in Brazil it posed as Modulo Seguranca Stone, likely pretending to be a security module for a local payment provider.

ThreatFabric also found fake overlay pages that Herodotus can display on top of legitimate apps used by banks and cryptocurrency platforms in the U.S., U.K., Turkey, Poland and other countries.

“Considering that the malware is still in an active development stage, we can expect Herodotus to further evolve and be used widely in global campaigns,” the company said.

Herodotus works like many modern Android banking trojans. Operators distribute it through SMS messages that trick users into downloading a malicious installer. Once installed, the malware waits for a targeted app to open and then overlays a fake screen that mimics the real banking or payment interface to steal credentials. It also intercepts incoming SMS messages to capture one-time passcodes and exploits Android’s accessibility features to read what’s shown on the device screen.

Buy JNews
ADVERTISEMENT

What makes Herodotus unusual, ThreatFabric said, is that it tries to “humanize” the actions attackers perform during remote control. Instead of pasting account or transaction details into form fields all at once — a behavior that can easily be flagged as automated — the malware types each character separately with random pauses of about 0.3 to 3 seconds between keystrokes, imitating how a real person would type.

ThreatFabric warned that the rise of mobile malware like Herodotus poses new challenges for banks and payment providers. Fraud controls that rely mainly on factors such as interaction tempo and keystroke cadence can still detect suspicious activity, but it’s most effective when paired with other security measures that monitor not only user behavior but also the device environment to identify threats like Herodotus, the company added.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.



Source link

Tags: AndroidDetectionEvadeHumanmalwaremimicsmoneyStealtyping
ShareTweetPin
Cyberinchief

Cyberinchief

Related Posts

Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
Cyber Crime

Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London

December 27, 2025
AI Expert: We Have 2 Years Before Everything Changes! We Need To Start Protesting! — Tristan Harris – Lifeboat News: The Blog
Cyber Crime

AI Expert: We Have 2 Years Before Everything Changes! We Need To Start Protesting! — Tristan Harris – Lifeboat News: The Blog

December 9, 2025
Russian police bust bank-account hacking gang that used NFCGate-based malware
Cyber Crime

Russian police bust bank-account hacking gang that used NFCGate-based malware

December 8, 2025
How To Reframe Cybersecurity Budget Requests And Get Them Approved
Cyber Crime

How To Reframe Cybersecurity Budget Requests And Get Them Approved

December 8, 2025
Contractors with hacking records accused of wiping 96 govt databases – Lifeboat News: The Blog
Cyber Crime

Contractors with hacking records accused of wiping 96 govt databases – Lifeboat News: The Blog

December 7, 2025
Maryland man sentenced for N. Korea IT worker scheme involving US government contracts
Cyber Crime

Maryland man sentenced for N. Korea IT worker scheme involving US government contracts

December 7, 2025
Next Post
Overcoming the Cybersecurity Professional’s Five Fatal Flaws | by Josue Martins | Josue Martins In Cyber Security

Overcoming the Cybersecurity Professional’s Five Fatal Flaws | by Josue Martins | Josue Martins In Cyber Security

Canada Fines Cybercrime Friendly Cryptomus $176M – Krebs on Security

Canada Fines Cybercrime Friendly Cryptomus $176M – Krebs on Security

Recommended Stories

₹12 Lakh Cyber Heist: CBI Officer’s Mind Hacked by Scammer! | Real Cyber Crime Story

₹12 Lakh Cyber Heist: CBI Officer’s Mind Hacked by Scammer! | Real Cyber Crime Story

November 13, 2025
Which Cyber Security Job Is Right for You? (Full Career Path Breakdown)

Which Cyber Security Job Is Right for You? (Full Career Path Breakdown)

November 27, 2025
Chiranjeevi Files Cyber Crime Complaint | Trendsetter Telugu

Chiranjeevi Files Cyber Crime Complaint | Trendsetter Telugu

November 1, 2025

Popular Stories

  • Allianz Life – 1,115,061 breached accounts

    Allianz Life – 1,115,061 breached accounts

    0 shares
    Share 0 Tweet 0
  • Prosper – 17,605,276 breached accounts

    0 shares
    Share 0 Tweet 0
  • साइबर अपराध | Illegal Payment Gateway & Rented Bank Accounts | MAMTA CHOPRA

    0 shares
    Share 0 Tweet 0
  • Miljödata – 870,108 breached accounts

    0 shares
    Share 0 Tweet 0
  • Snowflake Data Breach Explained: Lessons and Protection Strategies

    0 shares
    Share 0 Tweet 0

Search

No Result
View All Result

Recent Posts

  • Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
  • Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
  • Polisi kembali ungkap sindikat Cyber Crime kejahatan Internasional – iNews Malam 09/03

Categories

  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos

Newsletter

© 2025 All rights reserved by cyberinchief.com

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us

© 2025 All rights reserved by cyberinchief.com

Newsletter Signup

Subscribe to our weekly newsletter below and never miss the latest News.

Enter your email address

Thanks, I’m not interested