Manic Android Malware Can Steal Data Through Nearby Infected Devices
A new Android malware strain called Manic is targeting users across Europe and can exfiltrate stolen data through nearby infected devices when it cannot connect to its command-and-control (C2) server.
Active since at least February, Manic combines spyware, banking fraud, and remote-access capabilities. The malware targets at least 169 banking, government and eID, payment, cryptocurrency wallet, messaging, authentication, and two-factor authentication (2FA) applications.
Although Manic has been observed targeting users in several European countries, Ukraine appears to be its primary focus, particularly users of banking and government applications.
Manic Android malware uses accessibility services to spy on victims
Mobile security company ThreatFabric analyzed the Manic Android malware and found that it uses a transparent overlay on the numeric keypad of legitimate applications. The overlay captures a victim’s taps and reproduces them through Android Accessibility services, allowing the legitimate app to continue operating normally while Manic records the input.

Source: ThreatFabric
Once it obtains Accessibility and notification permissions, Manic can collect device lock PINs and passwords, intercept notifications and SMS messages, access files and location data, monitor the screen, and give its operators remote control through WebRTC sessions.
The malware categorizes the information it captures, making the stolen data easier for attackers to analyze and exploit.
“Manic uses accessibility services as a UI keylogger,” ThreatFabric explains. The researchers added that the malware “categorizes captured text before recording, distinguishing between lock screen inputs, recovery phrase suggestions, 4- to 6-digit SMS codes, passwords, long messages, email logins, and regular text.”
.jpg)
Source: ThreatFabric
Encrypted data can be relayed through nearby devices
Manic’s operators have also implemented an unusual data-exfiltration feature that activates when an infected Android device cannot reach its C2 server.
According to ThreatFabric, the malware encrypts stolen information and transfers it through nearby compromised devices using Wi-Fi Direct, Bluetooth, or Bluetooth Low Energy (BLE).
“Manic first attempts to use established Wi-Fi Direct peers and then queries Bluetooth and BLE peers to determine if there is internet connectivity,” ThreatFabric said.
“If desired, the malware can also use multi-hop routes, with newly queued items defaulting to up to four relay hops.”
This peer-to-peer relay mechanism allows Manic to exfiltrate data from an offline device as long as another infected device is within Wi-Fi or Bluetooth range. The compromised devices can effectively act as relays until the stolen data reaches a device with internet access.

Source: ThreatFabric
Manic targets banking, government, and cryptocurrency apps
ThreatFabric said Manic has targeted applications used across Central and Western Europe, including the United Kingdom, as well as Russia. However, the malware’s main focus appears to be Ukrainian banking and government/eID applications, along with global fintech and cryptocurrency services.
The exact infection method remains unknown. Researchers observed a wrapper delivering the primary payload to victims in late May, while the malware’s existing infrastructure expanded during the following months.
In July, attackers were seen using an updated wrapper with stronger anti-analysis protections and in-memory DEX loading. New control panels and application programming interfaces (APIs) were also added to the malware’s infrastructure.
How to protect Android devices from Manic malware
Android users should avoid downloading APK files from unfamiliar websites, unofficial app stores, or other obscure sources. Users should also deny Accessibility permissions unless they are requested by a trusted application that genuinely requires them.
Keeping Android and installed applications updated, reviewing notification and SMS permissions, and running Google Play Protect scans regularly can also help detect and remove known malware.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




