JAKARTA Cybersecurity is again rocked by the emergence of a new Android malware called Herodotus. This malicious program has unique capabilities: mimicking human behavior so that its activity is difficult for users to detect. Even more dangerous, this malware can take control of the phone and steal sensitive data such as passwords and two-factor authentication code (2FA).

Herodotus malware was first discovered by cybersecurity firm ThreatFabric. In a report quoted from Android Authority, they describe in detail how this malware operates. One of its main capabilities is to mimic user interactions such as tapping the screen or scrolling the app so that suspicious activity looks natural. In that way, users do not realize that the device is already infected.

Apart from cheating with man-made movements, Herodotus is also able to record keystrokes (keyloggers), monitor SMS messages to read OTP codes, and steal banking credentials. This combination makes it a serious threat that could lead to theft of money or burglary of digital accounts.

Although it sounds worrying, Android users can actually avoid this risk with a simple step: don't install apps from outside the Google Play Store. ThreatFabric confirms that so far no apps on the Play Store have been detected bringing Herodotus malware.

Google has also confirmed that Google Play Protect automatically protects Android devices from the previously identified Herodotus version. This feature is disabled on all Android devices with Google Play services, and will alert or block detected apps from behaving maliciously, including those downloaded from outside official stores.

Even so, threats can still come via fraudulent phishing links or short messages (SMS), known as smishing. ThreatFabric warns users not to carelessly click on suspicious links, especially those asking for account login or personal data.

With the increasingly sophisticated capabilities of malware such as Herodotus, digital awareness is the main bastion of defense. In an ecosystem that continues to grow, vigilance is not just an option, but a must because in the digital era, what looks 'human' is not necessarily human


The English, Chinese, Japanese, Arabic, and French versions are automatically generated by the AI. So there may still be inaccuracies in translating, please always see Indonesian as our main language. (system supported by DigitalSiber.id)