Image: ThreatFabric
At a glance
| Factor | Details |
|---|---|
| Malware Family | Manic |
| Threat Actor | Unknown organized criminal groups (Suspected) |
| Targets | Users of 169 banking, government, and messaging apps in Ukraine, Russia, and Europe |
| Delivery Vector | Malicious wrappers and software droppers |
| Key Capabilities | UI keylogging, device takeover, PIN capture, offline mesh relay data exfiltration |
| Source | ThreatFabric Mobile Threat Intelligence |
TL;DR
The Manic Android malware fuses banking trojan features with aggressive spyware functions to target mobile users. Specifically, this mobile threat captures lock-screen credentials and intercepts banking sessions directly on the device. Furthermore, the malware transfers stolen data through nearby infected phones when the victim lacks an active internet connection.
Delivery
Operators distribute Manic Android malware through malicious websites and software droppers. Initially, these malicious wrappers pose as legitimate booking or utility applications to trick unsuspecting victims. Once the user installs the dropper, the primary payload downloads and activates silently in the background. The timeline for this malicious activity dates back to February 2026, when attackers registered the initial infrastructure using fabricated identity details. Subsequently, the developers updated the deployment in July. This newer version added stronger anti-analysis checks, in-memory DEX loading, and lock-secret phishing capabilities. These rapid updates show that the software remains under active development.
Infection Chain
First, the malware prompts the user to grant Android Accessibility and notification permissions. After gaining this deep system access, the application hides its presence by removing its icon from the app drawer. Next, the malware captures the user’s lock-screen PIN or password by deploying an invisible capture layer over the screen.
According to ThreatFabric, the malware uses a feature called pinPadOverlay that “covers only the combined bounds of those keys and relays each tap to the same coordinates”. Therefore, this transparent layer allows the real banking application to process the input while the malware records the exact keystrokes. Beyond financial targets, the software targets users of 169 monitored package IDs across Ukraine, Russia, and Europe. These targets include major commercial messengers, military-focused communications, and government electronic identity services. By capturing this broad range of data, attackers can monitor both financial transactions and private conversations.
Command and Control and Data Exfiltration
After stealing credentials, the malware establishes a WebRTC connection with the command-and-control server. Consequently, this high-speed link allows operators to view the screen and control the device directly. Attackers can interact with the compromised phone just as if they held it in their hands. However, when a compromised device loses its internet connection, it activates a unique offline mesh relay system.
The malware encrypts the stolen data and searches for nearby infected devices. Specifically, it scans for these peers using Wi-Fi Direct, Bluetooth RFCOMM, or Bluetooth Low Energy connections. “If a suitable peer is found, the encrypted package is transferred to it and forwarded toward the C2 server”. Importantly, the routing system supports up to four network hops by default. As a result, disabling Wi-Fi or cellular data does not completely stop the data theft. A phone sitting completely offline can still transmit stolen data if another infected device passes within radio range.
Defense and Detection Guidance
Users should strictly avoid sideloading Android application packages from unverified websites or forums. Furthermore, device owners must exercise extreme caution before granting Accessibility permissions to any application. Security experts advise running regular Google Play Protect scans to detect malicious droppers early.
If administrators suspect an infection, they should physically separate the device from other mobile hardware. Because of the wireless mesh features, this physical isolation helps disrupt the local relay network.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.