A newly identified Android malware, known as Manic, is actively compromising financial institutions and critical services in Ukraine, Europe, and Russia. The sophisticated malware is targeting banks, government identity services, and messaging applications, among others, by combining financial fraud techniques with expansive surveillance capabilities.
Manic Malware: A Blend of Banking and Spyware
According to a report by ThreatFabric, Manic is a hybrid between Android banking malware and mobile spyware, leveraging features to both defraud and monitor. It targets sensitive applications and enables comprehensive device control, facilitating the relay of data through nearby infected devices using a Wi-Fi mesh network, especially when internet access is unavailable. The malware spreads via phishing websites and dropper apps disguised as legitimate utilities.
The malware’s history traces back to February 2026, with initial activities involving domain registration under a false identity. Subsequent developments led to the creation of a booking app-like wrapper and an implant, which evolved by July to include enhanced anti-analysis methods and phishing tactics for lock screen secrets.
Targets and Techniques: In-Depth Analysis
Manic’s reach is extensive, monitoring 169 package IDs across a wide array of applications, including banking, cryptocurrency services, and government apps. While primarily focused on Ukrainian entities, it also affects targets in Russia, Central and Western Europe, and the U.K. The malware’s design suggests its dual purpose: financial fraud and data surveillance.
In addition to financial applications, Manic also compromises military and commercial messaging apps, enabling the tracking of financial activities, communications, and user locations in real-time. The malware exploits Android’s accessibility services to capture screen secrets and create overlays, masking its operations with fake notifications and screens.
Unconventional Data Exfiltration Methods
Manic employs a unique store-and-forward relay mechanism to exfiltrate data, even when the primary device is offline. Through nearby compromised devices, the malware establishes a connection to the command-and-control server. This process involves staging encrypted files locally and relaying them through infected peers found via Wi-Fi Direct or Bluetooth.
The malware supports multi-hop routes, with the possibility of up to four relay hops by default, ensuring data transmission continuity even in the absence of direct internet access. This sophisticated approach underscores Manic’s ability to maintain operations and data theft without immediate online connectivity.
ThreatFabric’s report indicates that the developments observed from May to July 2026 demonstrate active enhancement of Manic’s capabilities, suggesting ongoing efforts to refine and expand its functionality.
As Manic continues to evolve, it presents a significant threat to Android users worldwide, highlighting the need for robust security measures and awareness to defend against such advanced cyber threats.
