A recent discovery in the world of Android malware reveals a new threat named Manic, which uniquely combines banking fraud with advanced spyware capabilities. One of its distinctive features is the ability to borrow an internet connection from nearby infected devices when the original device lacks connectivity.
Understanding the Threat of Manic Malware
Identified by ThreatFabric’s Mobile Threat Intelligence team, Manic is positioned at the crossroads of Android banking trojans and mobile spyware. Unlike traditional malware, Manic offers its operators a comprehensive fraud toolkit, including reading a victim’s PIN, observing live screen activities, hijacking banking sessions, and extracting files, messages, and location data.
Research indicates that Manic’s infrastructure dates back to February 2026, with rapid developments seen by mid-year. This advanced version demonstrates improved anti-analysis defenses and in-memory code loading, making it a formidable threat.
Targeted Applications and Geographic Focus
Currently, Manic targets 169 applications, including banks, government identity portals, payment services, cryptocurrency wallets, and messaging platforms. The primary focus is Ukraine, targeting national banks and eID services. However, its reach extends to Russia, Poland, Germany, the Czech Republic, Slovakia, and the UK, as well as international fintech and crypto platforms.
This diverse target list suggests that the operators aim not only for financial theft but also for insights into victims’ communications, including government and military messaging apps.
Innovative Techniques and Data Exfiltration
Unlike most banking trojans that use overlay attacks, Manic employs a different strategy by using a transparent layer over the numeric keypad of genuine banking apps to record PIN entries. These inputs are then replayed to the real app using Android’s Accessibility service, allowing transactions to proceed while logging the PIN.
Manic’s standout feature is its method of data exfiltration. When direct communication with its command-and-control server is blocked, it encrypts and stores data locally, seeking another infected device nearby with internet access. This secondary device then relays the data, creating a mesh network for data transfer, which complicates data containment efforts.
Security Implications and Recommendations
The combination of stealthy PIN capture, comprehensive device takeover, and a robust exfiltration network makes Manic more challenging to detect and contain compared to typical banking trojans. ThreatFabric’s continued monitoring of this malware, alongside other threats like WindRelay NFC and Herodotus trojans, highlights a trend of integrating multiple fraud techniques into single platforms.
To safeguard against such threats, it is crucial to avoid sideloading APKs from unofficial sources, scrutinize apps requesting Accessibility permissions, and keep Google Play Protect active. These steps can help mitigate the risks posed by Manic and similar malware families.
