ThreatLocker
  • Home
  • News
  • Security
  • New Manic Android malware can exfiltrate data through nearby devices

New Manic Android malware can exfiltrate data through nearby devices

  • August 20, 2026
  • 06:02 AM
  • 0

New Manic Android malware can exfiltrate data through nearby devices

A new Android malware named Manic targeting users in multiple European countries has a fallback mechanism for exfiltrating data through nearby infected devices.

The malware has been active since at least February and combines spyware, banking fraud, and remote control capabilities.

It targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA apps, with users in Ukraine being the primary focus.

Mobile security company ThreatFabric analyzed the Manic malware and found that it uses transparent overlays on the numeric keypads of legitimate applications to capture victims' taps and reproduce them through Android Accessibility, allowing the legitimate applications to continue functioning normally.

Overlays capturing user taps
Overlays capturing user taps
Source: ThreatFabric

After obtaining Accessibility and notification access permissions, the malware can capture the lock PIN/password, intercept notifications and SMS messages, collect files and location data, monitor the screen, and provide remote control to operators via WebRTC sessions.

The captured information is categorized by type, making the data more readily exploitable for the malware operators.

“Manic uses its Accessibility service as a UI keylogger,” ThreatFabric explains, adding that the malware “classifies captured text before recording it, distinguishing lock-screen input, recovery-phrase candidates, four- to six-digit SMS codes, passwords, long messages, email logins, and ordinary text.”

Manic's attack chain
Manic's attack chain
Source: ThreatFabric

Manic malware authors implemented an unusual data exfiltration mechanism that kicks in when a compromised device cannot reach the command-and-control (C2) server.

The researchers say that the data is encrypted and transferred via nearby compromised devices over Wi-Fi Direct or Bluetooth connections.

"Manic first attempts to use an established Wi-Fi Direct peer, then queries Bluetooth and BLE peers to determine whether they have internet connectivity," ThreatFabric says.

"If necessary, the malware can also use multi-hop routes, with newly queued items configured for a maximum of four relay hops by default."

This mechanism also allows data exfiltration even from offline devices, as long as another infected device is within WiFi or Bluetooth range.

Data relaying mechanism
Data relaying mechanism
Source: ThreatFabric

ThreatFabric says the malware targets applications used across Central and Western Europe, including the U.K., as well as Russia. However, its primary focus appears to be banking and government/eID applications in Ukraine, along with global fintech and cryptocurrency services.

Although the exact infection vector remains unknown, the researchers noticed in late May the use of a wrapper that delivered the main payload to victims, followed by an expansion of the existing infrastructure in the months that followed.

In July, an updated wrapper with stronger anti-analysis checks and in-memory DEX loading was observed in attacks, and a new panel and API also rolled out.

Android users are advised to avoid downloading APKs from obscure sources and unofficial portals, deny Accessibility permissions unless required by a trusted application, and regularly run Play Protect scans to detect and remove known malware.

Update 22/8 - Google sent the following statement about Manic malware: 

“Based on our current detection, no apps containing this malware are found on Google Play. Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services." - A Google spokesperson

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Related Articles:

ToxicPanda Android malware uses VPN permissions to block Google Play

RedHook Android malware now uses Wireless ADB for shell access

Android 17 adds ECH support to make web browsing harder to track

Hackers infect Android car head units with proxy botnet malware

Android malware combo takes out loans and relays victims' credit cards

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
Post a Comment Community Rules
You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

Login

Reporter

Help us understand the problem. What is going on with this comment?
SUBMIT