[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhzxqwG0sdyvVariL267tMw5jtbXuCvYoXmOPczAo5Ao":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"d0959101-b641-482d-af0a-cabcdbf34843","manic-android-malware-uses-wi-fi-mesh-to-exfiltrate-data-from-offline-devices","fb748abd-1d17-4a27-8e71-95bd3bceebcd","Manic Android Malware Uses Wi-Fi Mesh to Exfiltrate Data from Offline Devices","The Manic malware represents a significant escalation in mobile threat sophistication by leveraging a Wi-Fi mesh relay technique that bypasses the assumption that offline devices are safe from data exfiltration. Distributed through phishing sites and malicious dropper apps, it exploits users' lack of awareness around app sourcing and permission grants to establish a covert spyware and banking fraud foothold. What makes this particularly dangerous is that simply taking a device offline is no longer a sufficient defensive measure, as nearby compromised devices can act as unwitting data relays. This undermines traditional air-gap assumptions and highlights the critical need for layered mobile security controls beyond basic network isolation.","**Immediate actions:**\n- Restrict Android device settings to allow app installations only from verified official app stores (Google Play with Play Protect enabled).\n- Audit and revoke excessive Wi-Fi and location permissions from all non-essential applications on corporate and personal devices.\n- Deploy mobile threat defense (MTD) solutions capable of detecting anomalous Wi-Fi peer-to-peer mesh behavior.\n\n**Long-term improvements:**\n- Implement a formal Mobile Device Management (MDM) policy that enforces app allowlisting and prevents sideloading of APKs across all managed devices.\n- Conduct regular security awareness training specifically covering mobile phishing, dropper app risks, and safe app installation practices.\n- Establish network segmentation policies that isolate mobile devices onto dedicated VLANs with restricted lateral communication capabilities.\n\n**Detection measures:**\n- Enable continuous logging and monitoring of Wi-Fi Direct and peer-to-peer connection events on managed endpoints to detect mesh relay activity.\n- Integrate threat intelligence feeds covering mobile malware indicators of compromise (IoCs) into your SIEM for real-time alerting.\n- Perform periodic behavioral analysis of installed applications to identify unauthorized data exfiltration patterns targeting financial or messaging apps.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 9: Email and Web Browser Protections","CIS Control 13: Network Monitoring and Defense","NIST SP 800-124 Rev 2: Guidelines for Managing the Security of Mobile Devices","NIST AC-17: Remote Access","NIST SI-3: Malicious Code Protection","NIST SC-7: Boundary Protection","GDPR Article 32: Security of Processing","MITRE ATT&CK Mobile T1437: Standard Application Layer Protocol","MITRE ATT&CK Mobile T1430: Location Tracking","ITIL Service Security Management: Access and Endpoint Controls","published","2026-08-20T15:20:21.895525+00:00","2026-08-20T15:20:21.627+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fmanic-android-malware-exfiltrates-data.html","manic-android-malware-exfiltrates-data-from-offline-phones-via-nearby-infected-d-cde593","Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"9c98511f-6932-4b1f-9b66-ddf17c4b655f","2026-08-20","afternoon","ThreatNoir Afternoon Brief — August 20","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-20\u002Fthreatnoir-afternoon-brief-2026-08-20.mp3"]