An advanced banking trojan called Herodotus has emerged as a significant threat to Android users worldwide. Operating as Malware-as-a-Service , this malicious application disguises itself as a legitimate tool to trick users into downloading and installing an APK file outside of the official Play Store .

Once installed on a device, the trojan gains access to critical system permissions and can perform banking transactions directly on the user's behalf. The threat represents a worrying development in mobile malware, particularly because it remains largely invisible to traditional antivirus solutions, despite its obvious malicious intent.
See also: New analysis reveals the main features of LockBit 5.0
The malware is primarily spread through phishing campaigns SMS, with attackers sending deceptive links that direct victims to fraudulent download pages. Users unknowingly install the APK, giving Herodotus access to sensitive permissions, including accessibility features.
Pradeo security analysts discovered that the trojan then deploys overlay attacks , displaying fake screens on top of legitimate banking applications and allowing for credential theft and session hijacking.

Herodotus Banking Trojan: Detection Evasion
Herodotus uses advanced detection evasion tactics , specifically designed to bypass modern fraud detection systems. The malware mimics human behavior for its malicious actions , through intentional delays, micro-motions, and realistic keystroke patterns. This behavioral approach makes automated detection significantly more difficult .
See also: Fantasy Hub: New Android malware steals SMS and contacts
The trojan records both screen content and keystroke data, allowing attackers to monitor user activity in real time and perform transactions while the victim remains logged into their banking session.
Pradeo security analysts noted that when they searched for Herodotus samples in the signature database of a leading antivirus provider, the application did not trigger any alerts. This failure occurred despite the fact that the malware is easily identifiable through search engine queries.

Traditional antivirus solutions typically rely on known signatures and previously observed patterns of behavior. Herodotus bypasses these defenses because it operates via SMS phishing (an initial access vector), is installed from unknown sources, and only triggers dangerous activities after explicit user consent.
See also: LeakyInjector and LeakyStealer steal cryptocurrencies and browsing history
Effective defense requires detection of multiple indicators of compromise that work in sequence: suspicious SMS links, installations from untrusted sources, critical permission requests, and strange behaviors, including screen overlays and simulated interactions. Individually, these signals may seem harmless, but combined, they reveal an active attack that conventional antivirus protection consistently misses.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
