
A brand new Android malware named Manic focusing on customers in a number of European nations has a fallback mechanism for exfiltrating knowledge by means of close by contaminated gadgets.
The malware has been energetic since no less than February and combines adware, banking fraud, and distant management capabilities.
It targets no less than 169 banking, authorities/eID, fee, crypto pockets, messaging, and authenticator/2FA apps, with customers in Ukraine being the first focus.
Cell safety firm ThreatFabric analyzed the Manic malware and located that it makes use of clear overlays on the numeric keypads of reliable functions to seize victims’ faucets and reproduce them by means of Android Accessibility, permitting the reliable functions to proceed functioning usually.

Supply: ThreatFabric
After acquiring Accessibility and notification entry permissions, the malware can seize the lock PIN/password, intercept notifications and SMS messages, acquire information and site knowledge, monitor the display, and supply distant management to operators by way of WebRTC periods.
The captured data is categorized by kind, making the info extra readily exploitable for the malware operators.
“Manic makes use of its Accessibility service as a UI keylogger,” ThreatFabric explains, including that the malware “classifies captured textual content earlier than recording it, distinguishing lock-screen enter, recovery-phrase candidates, four- to six-digit SMS codes, passwords, lengthy messages, e mail logins, and atypical textual content.”
.jpg)
Supply: ThreatFabric
Manic malware authors applied an uncommon knowledge exfiltration mechanism that kicks in when a compromised machine can’t attain the command-and-control (C2) server.
The researchers say that the info is encrypted and transferred by way of close by compromised gadgets over Wi-Fi Direct or Bluetooth connections.
“Manic first makes an attempt to make use of a longtime Wi-Fi Direct peer, then queries Bluetooth and BLE friends to find out whether or not they have web connectivity,” ThreatFabric says.
“If obligatory, the malware may also use multi-hop routes, with newly queued gadgets configured for a most of 4 relay hops by default.”
This mechanism additionally permits knowledge exfiltration even from offline gadgets, so long as one other contaminated machine is inside WiFi or Bluetooth vary.

Supply: ThreatFabric
ThreatFabric says the malware targets functions used throughout Central and Western Europe, together with the U.Okay., in addition to Russia. Nevertheless, its main focus seems to be banking and authorities/eID functions in Ukraine, together with world fintech and cryptocurrency companies.
Though the precise an infection vector stays unknown, the researchers observed in late Could using a wrapper that delivered the principle payload to victims, adopted by an growth of the prevailing infrastructure within the months that adopted.
In July, an up to date wrapper with stronger anti-analysis checks and in-memory DEX loading was noticed in assaults, and a brand new panel and API additionally rolled out.
Android customers are suggested to keep away from downloading APKs from obscure sources and unofficial portals, deny Accessibility permissions except required by a trusted software, and commonly run Play Shield scans to detect and take away recognized malware.
Total prevention scores can disguise what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses approach by approach throughout 338 million simulations run in buyer manufacturing environments.

