Manic Android Malware Uses Nearby Devices to Steal Data

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Manic Android malware, documented by ThreatFabric, blends banking fraud with spyware capabilities and targets Ukrainian banks, government and identity services, and military-focused messaging, alongside Russian, European, and global fintech and cryptocurrency apps.
- The malware's Wi-Fi mesh relay lets offline infected devices stage encrypted data, locate a nearby compromised peer via Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT, and forward it to command-and-control, with a four-hop relay limit by default.
- Activity traces to February 2026 with the first domain registration; the booking-app wrapper and implant appeared by end of May, development was paused from late June to mid-July, and a hardened second deployment adding lock-screen phishing emerged around July 13.
- The implant monitors 169 package IDs spanning banks, P2P and Buy Now Pay Later services, cryptocurrency wallets and exchanges, messaging apps, government and eID services, browsers, authenticators, and email clients.
- Manic abuses Android accessibility and notification services to intercept keypad inputs, record one-time codes and recovery phrases, screenshot devices, enable location tracking, export contacts, SMS, and call history, and attempt to disable Google Play Protect via UI automation.
- The malware captures PIN codes by overlaying a transparent layer on legitimate numeric keypads, recording exact tap positions and replicating the input on the real keypad while the targeted app functions normally.
Why it matters: For defenders, Manic demonstrates that disconnecting an infected Android from the internet no longer guarantees containment, since the malware weaponizes a second compromised device as a gateway through Wi-Fi Direct, Bluetooth, or BLE. With 169 monitored app packages and active development documented through July 2026, security teams at Ukrainian, Russian, and European financial institutions face a concrete new exfiltration path to hunt for in incident response.
Ask SkimNews




