Sunday , September 13 2026
Herodotus

“Herodotus” Android Banking Malware Attacks Evading Traditional Antivirus

A new Android banking Trojan called Herodotus has emerged recently. It is offered as Malware-as-a-Service (MaaS) and pretends to be a legitimate app to trick users into installing an APK. After installation, it requests sensitive permissions and can control the device for banking transactions. A modern mobile attack, yet once again, largely invisible to most traditional antivirus solutions.

Herodotus in brief:

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

The banking trojan spreads via SMS phishing links that lead users to a fake page where they are urged to download an app. The victim installs an APK that is not from the Play Store.

Herodotus, once installed and given permissions, asks for critical permissions like Accessibility. It overlays fake screens on real apps to trick users and can capture screens and keystrokes for session takeover while the victim is logged in.

Herodotus avoids detection by anti-fraud systems by adding random delays, subtle movements, and realistic typing patterns to its actions.

Why an antivirus isn’t enough:

The Pradeo team checked for malware in a top antivirus database, but no alerts were triggered for the application. This means the antivirus didn’t detect the malicious app, despite it being easily found through a simple search engine.

Antivirus solutions primarily depend on known signatures and past behaviors. Malicious apps from SMS phishing, installed outside the Play Store, can evade detection, especially if their code is fresh and harmful actions activate post-installation with granted permissions.

Effective detection relies on connecting several indicators of compromise: a suspicious SMS link from an unknown source, installations from outside the app store, critical permission requests, and visible signs like screen overlays, fake interactions, or screen captures.

Individually, these signals may seem harmless, but together, and in their sequence, they clearly reveal an ongoing attack that an antivirus can easily miss.

How Pradeo Mobile Threat Defense blocks the attack:

Unlike an antivirus, a Mobile Threat Defense (MTD) solution observes the real behavior of the device and acts at every stage of the attack chain:

Phishing link blocking:
Thanks to the anti-phishing module built into the Pradeo Security application, access to the malicious page is directly prevented. The user never reaches the download page and therefore cannot retrieve the APK.

Prevention of risky installations :
Pradeo Mobile Threat Defense detects that an application originates from an unknown source and immediately alerts the security team to prevent potential compromise.

Monitoring of permissions and behaviors :

When an application requests critical permissions (such as Accessibility), Pradeo Mobile Threat Defense flags it as potentially malicious and quarantines it, preventing any device takeover or intrusive actions.

Our solution also monitors UI and system behaviors (overlays, simulated taps, abnormal network activity). At the first sign of a malicious overlay, access to sensitive applications is immediately blocked.

The Herodotus case clearly illustrates that antivirus solutions are not suited to modern mobile threats, which combine social engineering, off-store installations, and abuse of sensitive permissions.

To effectively protect collaborators and corporate data, deploying a Mobile Threat Defense (MTD) solution is now essential.

Check Also

cPanel

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow …