Find notable cyber news and cases, enriched with sources, timelines, and signals.

Herodotus Android malware humanized typing and UI automation activity

Malware Activity
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

The Herodotus Android malware family now uses random 0.3 to 3 second typing delays to make automated input look human and harder for security tools to detect. It is being delivered through SMS phishing and a custom dropper that pressures victims to grant Accessibility permissions on Android 13+. Once active, it can use overlays and UI automation to steal banking credentials and intercept 2FA codes. The result is a stealthier mobile fraud threat for affected Android users.

Related Happenings

NFCShare Android malware spreads via fake banking-app updates

Malware Activity
H score21 First: 09.06.2026 01:11 Last: 09.06.2026 01:11 Sources 1

About this happening: The **NFCShare Android malware** is being spread as **fake banking-app updates on GitHub**, broadening attacks against **customers of multiple banks and financial institutions acr...

NFCShare fake banking-app update phishing campaign

Campaign
H score40 First: 09.06.2026 01:11 Last: 09.06.2026 01:11 Sources 1

About this happening: The **NFCShare** phishing campaign is using **fake banking-app updates** on **GitHub** to steal **payment card data** from customers of multiple banks across **Europe**, expanding...

Google Gemini on Android notification-injection bypass using Fake Context Alignment

Technical Analysis
H score16 First: 03.06.2026 22:11 Last: 03.06.2026 22:11 Sources 1

About this happening: Researchers found a **notification-based prompt-injection bypass** in **Google Gemini on Android** that could turn hostile notification text into **unauthorized assistant actions*...

Google rolls out Android fake call detection against AI impersonation scam calls

Security Tool/Service
H score20 First: 03.06.2026 12:02 Last: 03.06.2026 12:02 Sources 1

About this happening: **Google** is rolling out **fake call detection** on **Android 12 and later** devices this month, giving users a built-in warning when a caller may be using **AI voice-cloning** o...

BTMOB Android MaaS platform expands low-code phishing payload production

Threat Actor Meta
H score21 First: 29.05.2026 00:10 Last: 29.05.2026 00:10 Sources 1

About this happening: **BTMOB** has been exposed as a **malware-as-a-service** Android trojan with a **builder interface**, making it easier for cybercriminals to mass-produce tailored phishing payload...

Timeline

  1. 28.10.2025 12:00 1 articles · 7mo ago

    Herodotus Android malware uses human-like typing delays

    Initial Disclosure

    Herodotus is a new Android malware family offered as malware-as-a-service and used against Italian and Brazilian users through SMS phishing that delivers a custom dropper, requests Accessibility access on Android 13 and later, and then uses overlays and UI automation to steal credentials, intercept 2FA codes, and capture screen content. The malware's humanizer types with random 0.3 to 3 second delays to mimic human behavior and evade timing-based detection, and seven distinct subdomains suggest spread by several threat actors.

    Show sources