A brand new Android menace codenamed Manic has been noticed actively concentrating on Ukrainian banks, authorities and id providers, and messaging functions, in addition to Russian and European monetary establishments, world fintech and cryptocurrency providers, and military-focused communications.
“Manic sits on the intersection of Android banking malware and cell spy ware, combining financial-fraud capabilities with broader surveillance and device-control options,” ThreatFabric said in a technical report shared with The Hacker Information.
The malware, moreover concentrating on delicate functions and enabling in depth system takeover, introduces a novel Wi‑Fi mesh approach that makes it doable for the contaminated units to relay information by way of close by compromised units with web entry. It is distributed by way of phishing websites and dropper apps impersonating utilities.
The Dutch safety firm stated the malware household’s exercise dates again to February 2026, when the primary area was registered with a fabricated persona. Energetic improvement efforts ensued not lengthy after, with the primary wrapper utilizing a reserving app lure and the implant showing by the top of Might.
However in an attention-grabbing twist, these efforts have been deserted from late June to mid-July, whereas indicators of a second deployment emerged round July 13. The newer iteration of the wrapper and the implant have been discovered to include stronger anti-analysis checks and the power to phishing lock display screen secrets and techniques. A corresponding panel and API subsequently went dwell between July 24 and 28.
The APK information linked to the wrapper and implant are beneath –
- tech.intel.dialer.updater (Wrapper)
- org.honor.safe.helper (Wrapper)
- org.lenovo.storage.processor (Implant)
- dev.huawei.media.helper (Implant)
An examination of the malware reveals that it screens 169 package deal IDs related to banks, peer-to-peer (P2P) fee and Purchase Now, Pay Later (BNPL) providers, cryptocurrency wallets and exchanges, messaging apps, authorities and eID providers, browsers, authenticators, and e-mail shoppers. Nearly all of the targets are Ukrainian, but in addition current within the listing are apps utilized in Russia, Central and Western Europe, and the U.Okay.
“The goal set suggests a mix of banking malware and spy ware,” ThreatFabric famous. “Monetary fraud seems to be a serious goal, with protection spanning banks, fee providers, cryptocurrency exchanges and wallets, authorities id apps, and authenticators.”
In tandem, Manic can be designed to focus on business and military-focused messaging apps. As a result of the malware facilitates location monitoring, notification monitoring, file assortment, and distant system surveillance, the broad concentrating on permits the operator to maintain tabs on a sufferer’s monetary exercise, communications, and their whereabouts in real-time.
Like different Android malware households, Manic achieves its targets by abusing Android’s accessibility services and notification permissions, successfully permitting it to seize lock display screen secrets and techniques or serve pretend overlays to collect delicate information or conceal malicious exercise by displaying black or replace screens.
Among the different noteworthy options of the malware are listed beneath –
- Intercept keypad interactions and acquire passwords, one-time codes, and restoration phrases
- Leverage accessibility providers as a “UI keylogger” to categorise and file textual content together with the app used, and if that app is on the malware’s goal listing
- Monitor the display screen and work together with the system remotely over a WebRTC session
- Take away the implant from the launcher
- Document present coordinates and timestamp (and allow system location, if not already)
- Take screenshots
- Export contacts, name historical past, SMS messages, and notifications
- Get hold of a listing of put in apps
- Ship SMS to a equipped phone quantity together with the supplied textual content
- Show bogus notifications
- Delete a specific native file
- Lock the display screen by way of the accessibility service
- Try to disable Google Play Defend by way of UI automation
On high of those capabilities, Manic can seize PIN codes by serving a clear overlay atop the official numeric keypad within the focused app. Thus, when a consumer faucets on the overlay, the malware data the precise faucet place and the close by UI aspect. It then briefly turns off contact interception and proceeds to duplicate the faucet on the precise keypad on the identical place by profiting from the accessibility providers API.
This, in flip, permits the focused app to operate usually, whereas the menace actor is in possession of the PIN code with out having to show a pretend banking interface.
“Persistence depends on background staff, alarms, and the Accessibility and notification providers,” ThreatFabric stated. “These elements preserve C2 communication, course of instructions, add queued information, and synchronize the offline mesh, with periodic execution each 10 to fifteen minutes relying on the construct.”
Maybe probably the most uncommon side of Manic is its store-and-forward relay mechanism to exfiltrate information utilizing one other system that is in shut bodily proximity to the compromised Android telephone if it can’t hook up with the attacker-controlled infrastructure.
With this strategy, the concept is to permit the supply system to stay offline whereas the malware makes an attempt to find a second contaminated system that may present an alternate pathway to the command-and-control (C2) server. The relay mechanism works like this –
- The collected information and command outcomes are staged in an encrypted format and positioned in a neighborhood queue
- Discover an contaminated peer close by utilizing Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT
- If a peer is situated, the encrypted package deal is relayed to it and forwarded towards the C2 server
Manic additionally helps multi-hop routes, enabling the queued objects to be configured for a most of 4 relay hops by default. If no friends are discovered, the info is saved within the queue, and the entire course of is retried later.
“Every newly queued merchandise receives a four-hop relay restrict by default, though the configuration can change that worth,” ThreatFabric advised The Hacker Information. “The relay metadata additionally carries the present hop rely. An internet peer can create a Wi‑Fi Direct group when it finds no friends. Each retained construct makes use of the identical community identify and tries to create the group as much as 3 times.”
This additionally signifies that disconnecting an contaminated system from the web doesn’t essentially forestall information exfiltration, as Manic can weaponize one other compromised Android system as a gateway.
“The evolution noticed between Might and July 2026, together with stronger anti-analysis measures and lock-secret phishing, signifies that Manic stays beneath energetic improvement and continues to develop its capabilities,” ThreatFabric stated.


