New Manic Android malware can exfiltrate data through nearby devices
Manic is a sophisticated Android malware active since at least February 2026, targeting users primarily in Ukraine and multiple European countries. It combines spyware, banking fraud, and remote control capabilities, targeting numerous banking, government/eID, payment, crypto wallet, messaging, and authenticator apps. The malware uses Android Accessibility services to capture sensitive inputs like PINs, passwords, and SMS codes via transparent overlays. Uniquely, it can exfiltrate data through nearby infected devices using Wi-Fi Direct or Bluetooth when direct internet access to its command-and-control server is unavailable, enabling multi-hop data relays. Infection vectors remain unknown, but the malware employs anti-analysis techniques and in-memory payload loading. Users are advised to avoid unofficial APK sources and restrict Accessibility permissions.
AI Analysis
Technical Summary
Manic is an Android malware family combining spyware, banking fraud, and remote control features. It targets at least 169 apps related to banking, government identification, payments, crypto wallets, messaging, and two-factor authentication, focusing primarily on Ukrainian users but also affecting Central and Western Europe and Russia. The malware uses Android Accessibility services to overlay numeric keypads, capturing user taps and reproducing them to avoid detection. It collects lock screen PINs/passwords, intercepts notifications and SMS, gathers files and location data, and enables remote control via WebRTC. Manic classifies captured text by type for easier exploitation. Its novel data exfiltration fallback uses encrypted transfers over Wi-Fi Direct or Bluetooth through nearby infected devices, supporting multi-hop relays up to four hops, allowing offline devices to still leak data if in proximity to infected peers. The infection vector is unknown, but recent updates include stronger anti-analysis and in-memory DEX loading. Mitigation includes avoiding unofficial APKs and denying Accessibility permissions to untrusted apps.
Potential Impact
Manic malware can steal sensitive user data including lock screen credentials, SMS codes, passwords, and other classified text inputs. It can intercept notifications and SMS messages, collect files and location data, and provide remote control to attackers. Its ability to exfiltrate data via nearby infected devices over Wi-Fi Direct or Bluetooth enables data leakage even when the device is offline or disconnected from the internet. This multi-hop relay capability increases the difficulty of containment and detection. The malware targets critical financial, government, and authentication applications, potentially enabling financial fraud, identity theft, and unauthorized account access.
Mitigation Recommendations
There is no vendor patch or official fix available as this is malware rather than a software vulnerability. Users should avoid downloading APKs from unofficial or obscure sources. Accessibility permissions should be granted only to trusted applications, as Manic abuses these permissions to capture sensitive input. Regularly running Google Play Protect scans can help detect and remove known malware variants. Network-level controls to monitor and restrict Wi-Fi Direct and Bluetooth connections may help limit the malware's fallback data exfiltration mechanism. Users and organizations should maintain vigilance for suspicious app behavior and unauthorized permissions.
New Manic Android malware can exfiltrate data through nearby devices
Description
Manic is a sophisticated Android malware active since at least February 2026, targeting users primarily in Ukraine and multiple European countries. It combines spyware, banking fraud, and remote control capabilities, targeting numerous banking, government/eID, payment, crypto wallet, messaging, and authenticator apps. The malware uses Android Accessibility services to capture sensitive inputs like PINs, passwords, and SMS codes via transparent overlays. Uniquely, it can exfiltrate data through nearby infected devices using Wi-Fi Direct or Bluetooth when direct internet access to its command-and-control server is unavailable, enabling multi-hop data relays. Infection vectors remain unknown, but the malware employs anti-analysis techniques and in-memory payload loading. Users are advised to avoid unofficial APK sources and restrict Accessibility permissions.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Manic is an Android malware family combining spyware, banking fraud, and remote control features. It targets at least 169 apps related to banking, government identification, payments, crypto wallets, messaging, and two-factor authentication, focusing primarily on Ukrainian users but also affecting Central and Western Europe and Russia. The malware uses Android Accessibility services to overlay numeric keypads, capturing user taps and reproducing them to avoid detection. It collects lock screen PINs/passwords, intercepts notifications and SMS, gathers files and location data, and enables remote control via WebRTC. Manic classifies captured text by type for easier exploitation. Its novel data exfiltration fallback uses encrypted transfers over Wi-Fi Direct or Bluetooth through nearby infected devices, supporting multi-hop relays up to four hops, allowing offline devices to still leak data if in proximity to infected peers. The infection vector is unknown, but recent updates include stronger anti-analysis and in-memory DEX loading. Mitigation includes avoiding unofficial APKs and denying Accessibility permissions to untrusted apps.
Potential Impact
Manic malware can steal sensitive user data including lock screen credentials, SMS codes, passwords, and other classified text inputs. It can intercept notifications and SMS messages, collect files and location data, and provide remote control to attackers. Its ability to exfiltrate data via nearby infected devices over Wi-Fi Direct or Bluetooth enables data leakage even when the device is offline or disconnected from the internet. This multi-hop relay capability increases the difficulty of containment and detection. The malware targets critical financial, government, and authentication applications, potentially enabling financial fraud, identity theft, and unauthorized account access.
Defensive Guidance
There is no vendor patch or official fix available as this is malware rather than a software vulnerability. Users should avoid downloading APKs from unofficial or obscure sources. Accessibility permissions should be granted only to trusted applications, as Manic abuses these permissions to capture sensitive input. Regularly running Google Play Protect scans can help detect and remove known malware variants. Network-level controls to monitor and restrict Wi-Fi Direct and Bluetooth connections may help limit the malware's fallback data exfiltration mechanism. Users and organizations should maintain vigilance for suspicious app behavior and unauthorized permissions.
Technical Details
- Classification
- {"confidence":0.6,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a86d1d2acd9273b4972148f
Added to database: 08/20/2026, 10:07:14 UTC
Last enriched: 08/20/2026, 10:07:28 UTC
Last updated: 08/20/2026, 10:33:16 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.