PULSE NAME
New Android Malware Mimics Human Behavior to Evade Detection
WHITE K1R0 AlienVault 2025-10-28 Modified: 2025-10-28
3
IOCs
LOW VOLUME
A new Android malware called Herodotus has been discovered, designed to perform device takeover while mimicking human behavior to bypass biometric detection. Active campaigns have been observed in Italy and Brazil. Herodotus is being offered as Malware-as-a-Service and shows links to the previously known Brokewell malware. It uses side-loading for distribution and employs various techniques to steal credentials and perform remote device control. A unique feature is its attempt to humanize remote actions by randomizing delays between text inputs. The malware targets financial organizations and crypto wallets, with potential for global expansion. Its development highlights the growing threat of Device-Takeover banking Trojans and the need for advanced, layered security approaches.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (3)
All FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 53ee40353e17d069b7b7783529edda968ad9ae25a0777f6a644b99551b412083 2025-10-28
domain google-firebase.digital 2025-10-28
hostname gj23j4jg.google-firebase.digital 2025-10-28