Cybersecurity

Manic Android malware exfiltrates data through nearby infected devices

ThreatFabric identified an Android malware strain named Manic that combines espionage, banking fraud, and remote control, targeting at least 169 applications. The malware can relay stolen data through nearby infected devices using Wi‑Fi Direct or Bluetooth, even when the victim device is offline.

2026-08-20
3 min read
19 views
فريق تحرير certi.news
Manic Android malware exfiltrates data through nearby infected devices

Mobile security company ThreatFabric identified a new Android malware strain named Manic, active since at least February 2026 and targeting users in several European countries, with a clear focus on banking, government, and digital identity applications in Ukraine. The malware combines espionage, banking fraud, and remote-control capabilities, while its architecture includes an unusual mechanism for exfiltrating data through infected devices located near the targeted device.

Manic targets at least 169 applications, including banking and government services, payment applications, cryptocurrency wallets, messaging platforms, and two-factor authentication applications. Researchers also observed targeting of fintech and cryptocurrency services worldwide, along with applications used in Central and Western Europe, the United Kingdom, and Russia.

How does Manic collect victims’ data?

After obtaining Accessibility Service and notification access permissions, the malware can capture the device lock code or password, read notifications and text messages, collect files and location data, monitor the screen, and give operators the ability to control the device remotely through WebRTC sessions.

Manic uses transparent layers over digital keyboards within legitimate applications to capture user keystrokes and replay them through Android Accessibility, allowing the original application to continue operating normally. ThreatFabric describes this functionality as a “UI keylogger”; it classifies the text it captures before storing it to distinguish lock-screen inputs, potential wallet recovery phrases, four- to six-digit SMS codes, passwords, email login details, long messages, and ordinary text.

What makes the exfiltration mechanism distinctive?

When the infected device cannot access the command-and-control server, Manic encrypts the data and transfers it through nearby infected devices using Wi‑Fi Direct or Bluetooth. The malware first attempts to use an existing Wi‑Fi Direct peer, then queries nearby devices using Bluetooth or BLE to determine whether they have an internet connection.

The mechanism supports multi-hop routes, with new entries configured by default with a maximum of four relay stages. In practice, this means that a device without an internet connection may still be able to send stolen data if another infected device is within Wi‑Fi or Bluetooth range, increasing the chances that the information will reach the malware’s operators.

Evolution of the attack infrastructure

ThreatFabric has not yet precisely identified the original infection method, but in late May it observed the use of a software wrapper that delivered the main payload to victims, followed by an expansion of the infrastructure over the following months. In July, an updated version of the wrapper appeared with stronger anti-analysis checks and in-memory loading of DEX-format executables, along with a new control panel and API.

What should Android users do?

Users should avoid downloading APK files from obscure sources or unofficial portals and should not grant Accessibility permission except to a trusted application that genuinely needs it. They are also advised to run Play Protect scans regularly to detect and remove known malware.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news