Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

New Manic Android malware can exfiltrate data through nearby devices

0
High
Published: 08/20/2026 (08/20/2026, 10:02:02 UTC)
Source: Bleeping Computer

Description

Manic is a sophisticated Android malware active since at least February 2026, targeting users primarily in Ukraine and multiple European countries. It combines spyware, banking fraud, and remote control capabilities, targeting numerous banking, government/eID, payment, crypto wallet, messaging, and authenticator apps. The malware uses Android Accessibility services to capture sensitive inputs like PINs, passwords, and SMS codes via transparent overlays. Uniquely, it can exfiltrate data through nearby infected devices using Wi-Fi Direct or Bluetooth when direct internet access to its command-and-control server is unavailable, enabling multi-hop data relays. Infection vectors remain unknown, but the malware employs anti-analysis techniques and in-memory payload loading. Users are advised to avoid unofficial APK sources and restrict Accessibility permissions.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 10:07:28 UTC

Technical Analysis

Manic is an Android malware family combining spyware, banking fraud, and remote control features. It targets at least 169 apps related to banking, government identification, payments, crypto wallets, messaging, and two-factor authentication, focusing primarily on Ukrainian users but also affecting Central and Western Europe and Russia. The malware uses Android Accessibility services to overlay numeric keypads, capturing user taps and reproducing them to avoid detection. It collects lock screen PINs/passwords, intercepts notifications and SMS, gathers files and location data, and enables remote control via WebRTC. Manic classifies captured text by type for easier exploitation. Its novel data exfiltration fallback uses encrypted transfers over Wi-Fi Direct or Bluetooth through nearby infected devices, supporting multi-hop relays up to four hops, allowing offline devices to still leak data if in proximity to infected peers. The infection vector is unknown, but recent updates include stronger anti-analysis and in-memory DEX loading. Mitigation includes avoiding unofficial APKs and denying Accessibility permissions to untrusted apps.

Potential Impact

Manic malware can steal sensitive user data including lock screen credentials, SMS codes, passwords, and other classified text inputs. It can intercept notifications and SMS messages, collect files and location data, and provide remote control to attackers. Its ability to exfiltrate data via nearby infected devices over Wi-Fi Direct or Bluetooth enables data leakage even when the device is offline or disconnected from the internet. This multi-hop relay capability increases the difficulty of containment and detection. The malware targets critical financial, government, and authentication applications, potentially enabling financial fraud, identity theft, and unauthorized account access.

Defensive Guidance

There is no vendor patch or official fix available as this is malware rather than a software vulnerability. Users should avoid downloading APKs from unofficial or obscure sources. Accessibility permissions should be granted only to trusted applications, as Manic abuses these permissions to capture sensitive input. Regularly running Google Play Protect scans can help detect and remove known malware variants. Network-level controls to monitor and restrict Wi-Fi Direct and Bluetooth connections may help limit the malware's fallback data exfiltration mechanism. Users and organizations should maintain vigilance for suspicious app behavior and unauthorized permissions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.6,"severitySource":"default","classifier":"rss-v2"}

Threat ID: 6a86d1d2acd9273b4972148f

Added to database: 08/20/2026, 10:07:14 UTC

Last enriched: 08/20/2026, 10:07:28 UTC

Last updated: 08/20/2026, 10:33:16 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses