{"id":262571,"date":"2025-10-31T09:21:31","date_gmt":"2025-10-31T09:21:31","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/262571\/"},"modified":"2025-10-31T09:21:31","modified_gmt":"2025-10-31T09:21:31","slug":"new-android-warning-as-humanized-password-stealer-confirmed","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/262571\/","title":{"rendered":"New Android Warning As Humanized Password Stealer Confirmed"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/10\/1761902491_139_960x0.jpg\" alt=\"Android logo on smartphone, with zoomed in Android robot face in background.\" data-height=\"1807\" data-width=\"2711\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Beware this humanized password stealer.<\/p>\n<p>SOPA Images\/LightRocket via Getty Images<\/p>\n<p>Updated October 29 with a  statement from Google concerning the latest threat to Android users and how they are being protected from the Herodotus malware.<\/p>\n<p>Well, it\u2019s been quite the week or so for Google users. What with the news that <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/28\/gmail-passwords-confirmed-as-part-of-183-million-account-data-breach\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/28\/gmail-passwords-confirmed-as-part-of-183-million-account-data-breach\/\" target=\"_self\" aria-label=\"Gmail passwords\" rel=\"nofollow noopener\">Gmail passwords<\/a> were confirmed as being included as part of a 183 million credentials infostealer log, two <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/28\/gmail-passwords-confirmed-as-part-of-183-million-account-data-breach\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/28\/gmail-passwords-confirmed-as-part-of-183-million-account-data-breach\/\" target=\"_self\" aria-label=\"emergency security updates\" rel=\"nofollow noopener\">emergency security updates<\/a> for Chrome, and an announcement of a wait until October 2026 for <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/28\/google-says-chrome-will-be-more-secure-for-billions---in-october-2026\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/28\/google-says-chrome-will-be-more-secure-for-billions---in-october-2026\/\" target=\"_self\" aria-label=\"HTTPS by default\" rel=\"nofollow noopener\">HTTPS by default<\/a> for Chrome browser users as well. Now, harking back to credential-stealers once more, comes the confirmation of a new threat to Android users in the shape of the Herodotus malware that can bypass biometric detection by mimicking human behavior. Here\u2019s what you need to know. <\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/29\/update-now-as-microsoft-confirms-new-windows-admin-protection\/\" target=\"_blank\" aria-label=\"Update Now As Microsoft Confirms New Windows Admin Protection\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/29\/update-now-as-microsoft-confirms-new-windows-admin-protection\/\" rel=\"nofollow noopener\">ForbesUpdate Now As Microsoft Confirms New Windows Admin ProtectionBy Davey Winder<\/a>The Android User Threat Posed By Herodotus<\/p>\n<p>Newly published research from mobile threat intelligence specialists ThreatFabric has confirmed that a nasty piece of Android malware called Herodotus can mimic human typing and other behaviors to steal passwords and financial credentials while bypassing biometric detection protections.<\/p>\n<p>\u201cDuring routine monitoring of malicious distribution channels,\u201d the ThreatFabric report stated, \u201cthe Mobile Threat Intelligence service discovered unknown malicious samples.\u201d These turned out to be a new Android banking trojan by the name of Herodotus which, <a class=\"color-link\" href=\"https:\/\/www.threatfabric.com\/blogs\/new-android-malware-herodotus-mimics-human-behaviour-to-evade-detection\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.threatfabric.com\/blogs\/new-android-malware-herodotus-mimics-human-behaviour-to-evade-detection\" aria-label=\"the analysts said\">the analysts said<\/a>, introduces \u201cgroundbreaking techniques to evade detection systems,\u201d to the mobile threat landscape. <\/p>\n<p>This is no idea threat or research that is confined to security research labs, either. Active attack campaigns have already been identified in Brazil and Italy, and there is no reason to suspect they will not spread further afield as the malware-as-a-service offering is currently being marketed on underground cybercriminal forums. <\/p>\n<p>What flags Herodotus as being different to other banking trojans, the report warned,  is the ability to mimic human behaviour during remote control sessions. \u201cThe trojan deploys fake credential-harvesting screens over legitimate banking applications,\u201d ThreatFabric said, \u201ccapturing login credentials and two-factor authentication codes through SMS interception.\u201d But the text input automation during an attack employs \u201ca novel technique where operator-specified text is split into individual characters, with each character set separately at randomized intervals.\u201d<\/p>\n<p>This human-like typing, with random delays of set text events of between 300 to 3000 milliseconds between character input, can evade those biometric protection systems that measure such typing timing. \u201cAndroid malware containing delays in input is not in itself uncommon,\u201d Aditya Sood, vice-president of Security Engineering at Aryaka, told me, \u201cas they\u2019re typically implemented to allow targeted app UIs to respond to inputs.\u201d But Sood warned that the random nature of the delays, in both frequency and duration, is problematic. \u201cThis is a novel technique, and while it&#8217;s still under development, successful Brazilian and Italian phishing campaigns exemplify its dangerous potential.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/26\/paypal-users-warned-do-not-pay-do-not-phone-as-attackers-strike\/\" target=\"_blank\" aria-label=\"PayPal Users Warned \u2018Do Not Pay, Do Not Phone\u2019 As Attackers Strike\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/26\/paypal-users-warned-do-not-pay-do-not-phone-as-attackers-strike\/\" rel=\"nofollow noopener\">ForbesPayPal Users Warned \u2018Do Not Pay, Do Not Phone\u2019 As Attackers StrikeBy Davey Winder<\/a><\/p>\n<p>\u201cBased on our current detection, no apps containing this malware are found on Google Play. Android users are automatically protected against known versions of this malware by <a href=\"https:\/\/support.google.com\/googleplay\/answer\/2812853?hl=en\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/support.google.com\/googleplay\/answer\/2812853?hl=en\" aria-label=\"Google Play Protect\">Google Play Protect<\/a>, which is on by default on Android devices with Google Play Services. Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play,\u201d a Google spokesperson said.<\/p>\n","protected":false},"excerpt":{"rendered":"Beware this humanized password stealer. SOPA Images\/LightRocket via Getty Images Updated October 29 with a statement from Google&hellip;\n","protected":false},"author":2,"featured_media":262572,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[41],"tags":[4329,141476,18382,141478,4001,141475,2631,141474,165,141477,74],"class_list":["post-262571","post","type-post","status-publish","format-standard","has-post-thumbnail","category-mobile","tag-android","tag-android-credential-stealer","tag-android-security","tag-cyber-research","tag-cybercrime","tag-herodotus","tag-human","tag-infostealer","tag-mobile","tag-password-stealer","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/262571","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=262571"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/262571\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/262572"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=262571"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=262571"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=262571"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}