[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTYq0UcwlX-wHSxAVAJyaluaEKo_SYg3_C8lLrxih38o":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"cd8dfa77-af86-4e21-818b-9ed7d900525b","manic-android-malware-exfiltrates-data-via-nearby-infected-devices","b7701228-57db-4789-a1d6-087a2ae4e7be","Manic Android Malware Exfiltrates Data via Nearby Infected Devices","The Manic Android malware represents a sophisticated evolution in mobile threats by leveraging Wi-Fi Direct and Bluetooth as fallback data exfiltration channels, allowing it to bypass traditional network-based defenses even on offline devices. This peer-to-peer relay technique means that a single compromised device in proximity to another infected device can serve as an unwitting data mule, making conventional perimeter controls insufficient. The malware's focus on banking, government, and cryptocurrency applications highlights how threat actors are increasingly targeting high-value credentials and financial assets. This matters because organizations can no longer assume air-gapped or offline devices are safe when physical proximity to other compromised endpoints becomes a viable attack vector.","**Immediate actions:**\n- Audit and restrict permissions for Bluetooth and Wi-Fi Direct on all corporate and government-issued Android devices.\n- Deploy a mobile threat defense (MTD) solution capable of detecting anomalous peer-to-peer communication patterns on managed devices.\n- Warn employees in targeted sectors (banking, government, crypto) about unsolicited app installs and sideloading risks.\n\n**Long-term improvements:**\n- Enforce a Mobile Device Management (MDM) policy that disables Wi-Fi Direct and Bluetooth when not explicitly required by business function.\n- Implement network segmentation so mobile devices operate on isolated VLANs, limiting lateral data movement opportunities.\n- Establish a formal mobile application allowlist policy, permitting only vetted apps from official stores on devices with access to sensitive systems.\n\n**Detection measures:**\n- Enable continuous logging of Bluetooth and Wi-Fi Direct connection events on managed endpoints and forward logs to a SIEM for anomaly detection.\n- Configure alerts for unauthorized banking, government, or crypto application access attempts originating from mobile endpoints.\n- Conduct regular threat hunting exercises specifically targeting indicators of compromise (IoCs) associated with Manic and similar mobile spyware families.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 6: Access Control Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-124: Guidelines for Managing the Security of Mobile Devices","NIST AC-17: Remote Access","NIST SC-7: Boundary Protection","NIST SI-3: Malicious Code Protection","GDPR Article 32: Security of Processing (for EU-targeted data exfiltration)","ENISA Mobile Threats Taxonomy","MITRE ATT&CK Mobile T1437: Application Layer Protocol","MITRE ATT&CK Mobile T1646: Exfiltration Over C2 Channel","published","2026-08-20T12:22:09.185095+00:00","2026-08-20T12:22:08.916+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-manic-android-malware-can-exfiltrate-data-through-nearby-devices\u002F","new-manic-android-malware-can-exfiltrate-data-through-nearby-devices-7aa101","New Manic Android malware can exfiltrate data through nearby devices",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]