The Containment Era is here. →Explore

Executive Summary

In October 2025, cybersecurity researchers uncovered a new Android banking trojan, dubbed Herodotus, actively targeting financial institutions and users in Italy and Brazil. The malware stands out by performing sophisticated device takeover (DTO) attacks while mimicking genuine human behavior—specifically attempting to bypass behavioral biometrics and anti-fraud detection. Herodotus infects devices via malicious apps or phishing, granting attackers near-complete control, which they use to exfiltrate sensitive financial and authentication data by simulating legitimate user interaction.

The Herodotus incident underscores a troubling advancement in mobile malware—attackers are increasingly leveraging techniques that closely imitate human behavior to elude cutting-edge security controls. This signals a growing risk for banking apps and enterprises relying on behavioral biometrics, and highlights the urgent need for multilayered zero trust strategies and improved east-west visibility in mobile ecosystems.

Why This Matters Now

Herodotus represents a shifting threat landscape: malware is now engineered to circumvent behavioral biometrics by emulating natural user input. With mobile banking growing rapidly, this evasion technique raises the stakes for organizations relying exclusively on behavior detection, demanding urgent innovation in endpoint protection and security framework adoption.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Herodotus mimicked human behavior, such as typing speed and touch patterns, enabling it to bypass behavioral biometrics defenses within financial applications.

Cloud Native Security Fabric Mitigations and ControlsCNSF

CNSF and Zero Trust controls, such as segmentation, egress enforcement, east-west traffic visibility, and real-time threat detection, would inhibit malware propagation, detect anomalous behaviors, and restrict C2/exfiltration paths, thus severely limiting Herodotus impact.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Anomalous device behaviors are rapidly detected, triggering containment.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Escalated entities are restricted in lateral network movement.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Unusual lateral or service-to-service flows are blocked and alerted.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Outbound C2 and unknown destinations are blocked by policy.

Exfiltration

Control: Cloud Firewall (ACF)

Mitigation: Data loss via outbound channels is detected and prevented.

Impact (Mitigations)

Autonomous enforcement isolates impacted workloads before major harm.

Impact at a Glance

Affected Business Functions

  • Online Banking
  • Mobile Payments
  • Customer Account Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive customer data, including banking credentials and personal information, due to unauthorized access and data exfiltration by the Herodotus malware.

Recommended Actions

  • Implement real-time anomaly detection to rapidly identify device takeover or unusual user behaviors across cloud endpoints.
  • Enforce granular east-west traffic controls and microsegmentation to restrict lateral movement by malware within cloud environments.
  • Apply strict egress filtering and DNS/FQDN controls to disrupt C2 channels and block exfiltration attempts.
  • Utilize zero trust segmentation and least privilege policies to minimize attacker lateral expansion after initial compromise.
  • Deploy centralized threat visibility and automated response to accelerate detection, policy enforcement, and containment.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image