Back to Feed
MalwareAug 20, 2026

New Manic Android malware can exfiltrate data through nearby devices

New Android malware 'Manic' uses nearby infected devices for data exfiltration.

Summary

A new Android malware named Manic, active since February, targets users in Europe with spyware, banking fraud, and remote control capabilities. It employs a unique fallback mechanism to exfiltrate data through nearby infected devices via Wi-Fi Direct or Bluetooth, even from offline devices, if direct C2 communication fails. The malware focuses on banking, government, and crypto apps, with a primary emphasis on Ukraine.

Full text

New Manic Android malware can exfiltrate data through nearby devices By Bill Toulas August 20, 2026 06:02 AM 0 A new Android malware named Manic targeting users in multiple European countries has a fallback mechanism for exfiltrating data through nearby infected devices. The malware has been active since at least February and combines spyware, banking fraud, and remote control capabilities. It targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA apps, with users in Ukraine being the primary focus. Mobile security company ThreatFabric analyzed the Manic malware and found that it uses transparent overlays on the numeric keypads of legitimate applications to capture victims' taps and reproduce them through Android Accessibility, allowing the legitimate applications to continue functioning normally. Overlays capturing user tapsSource: ThreatFabric After obtaining Accessibility and notification access permissions, the malware can capture the lock PIN/password, intercept notifications and SMS messages, collect files and location data, monitor the screen, and provide remote control to operators via WebRTC sessions. The captured information is categorized by type, making the data more readily exploitable for the malware operators. “Manic uses its Accessibility service as a UI keylogger,” ThreatFabric explains, adding that the malware “classifies captured text before recording it, distinguishing lock-screen input, recovery-phrase candidates, four- to six-digit SMS codes, passwords, long messages, email logins, and ordinary text.” Manic's attack chainSource: ThreatFabric Manic malware authors implemented an unusual data exfiltration mechanism that kicks in when a compromised device cannot reach the command-and-control (C2) server. The researchers say that the data is encrypted and transferred via nearby compromised devices over Wi-Fi Direct or Bluetooth connections. "Manic first attempts to use an established Wi-Fi Direct peer, then queries Bluetooth and BLE peers to determine whether they have internet connectivity," ThreatFabric says. "If necessary, the malware can also use multi-hop routes, with newly queued items configured for a maximum of four relay hops by default." This mechanism also allows data exfiltration even from offline devices, as long as another infected device is within WiFi or Bluetooth range. Data relaying mechanismSource: ThreatFabric ThreatFabric says the malware targets applications used across Central and Western Europe, including the U.K., as well as Russia. However, its primary focus appears to be banking and government/eID applications in Ukraine, along with global fintech and cryptocurrency services. Although the exact infection vector remains unknown, the researchers noticed in late May the use of a wrapper that delivered the main payload to victims, followed by an expansion of the existing infrastructure in the months that followed. In July, an updated wrapper with stronger anti-analysis checks and in-memory DEX loading was observed in attacks, and a new panel and API also rolled out. Android users are advised to avoid downloading APKs from obscure sources and unofficial portals, deny Accessibility permissions unless required by a trusted application, and regularly run Play Protect scans to detect and remove known malware. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: RedHook Android malware now uses Wireless ADB for shell accessAndroid malware combo takes out loans and relays victims' credit cardsGoogle says Chrome cuts 7 billion unwanted Android notifications a day to fight abuseInside the Underground Business of the Android BTMOB RAT malwareSakura Internet hack exposes data of up to 1.36 million accounts

Indicators of Compromise

  • malware — Manic

Entities

Android (product)Wi-Fi Direct (technology)Bluetooth (technology)WebRTC (technology)Android Accessibility (technology)