Manic Malware Drains Offline Android Phones via Nearby Devices

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- ThreatFabric identified "Manic," a new Android malware targeting Ukrainian banks, government and eID services, and messaging apps, alongside Russian, Central and Western European, U.K., and global fintech and cryptocurrency platforms — monitoring 169 package IDs in total.
- Manic introduces a novel store-and-forward Wi-Fi mesh relay, allowing offline infected phones to queue encrypted data and forward it through up to four nearby compromised devices via Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT connections.
- The malware family traces back to a February 2026 domain registration using a fabricated persona; after a pause from late June to mid-July, a second iteration emerged around July 13 with stronger anti-analysis checks and lock-screen phishing, with a panel and API going live between July 24 and 28.
- Manic combines banking-trojan functionality with spyware, abusing Android accessibility services to serve transparent overlays that capture PIN codes by replicating taps on legitimate numeric keypads without displaying fake interfaces.
- Capabilities include remote device control over WebRTC, screenshots, contacts/SMS/call-history export, real-time location tracking, and attempts to disable Google Play Protect through UI automation.
- ThreatFabric flagged Manic as sitting "at the intersection of Android banking malware and mobile spyware," with persistence via background workers, alarms, and C2 sync every 10 to 15 minutes, distributed through phishing sites and droppers impersonating utilities like booking apps.
Why it matters: Air-gapping or disconnecting a compromised phone no longer contains the breach — Manic weaponizes any nearby infected Android as a relay, meaning one connected device can drain queued data from multiple offline phones sharing physical space. For the 169 targeted apps spanning Ukrainian banking, crypto wallets, and military messaging, the design turns casual proximity into a multi-hop exfiltration path.
Ask SkimNews




