A new Android malware family named Manic has been discovered by ThreatFabric, actively targeting Ukrainian banks, government and identity services, messaging apps, as well as Russian and European financial institutions, global fintech, cryptocurrency services, and military-focused communications. The malware combines banking trojan and spyware capabilities, enabling financial fraud, surveillance, and device takeover.
Manic is distributed via phishing sites and dropper apps impersonating utilities. It abuses Android accessibility services and notification permissions to capture lock screen secrets, intercept keypad inputs, and display fake overlays. The malware monitors 169 package IDs, including banking, payment, crypto, messaging, government eID, and email apps.
A notable feature is its Wi-Fi mesh technique, allowing infected devices to relay data through nearby compromised devices with internet access, even when the source device is offline. The relay uses Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT, supporting multi-hop routes with a default maximum of four hops. This ensures data exfiltration continues even if the infected device is disconnected from the internet.
Manic’s activity dates back to February 2026, with active development observed through July 2026. The malware includes anti-analysis checks, lock screen secret phishing, and remote device control via WebRTC. It can record coordinates, take screenshots, export contacts and messages, send SMS, and disable Google Play Protect.
ThreatFabric notes that Manic remains under active development, expanding its capabilities. The malware’s blend of banking fraud and espionage makes it a significant threat to financial and government sectors.
Malware: Manic
Companies: ThreatFabric
Original source: thehackernews.com