Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Android Malware Manic Exploits Banking Security

New Android Malware Manic Exploits Banking Security

Posted on August 20, 2026 By CWS

A recent discovery in the world of Android malware reveals a new threat named Manic, which uniquely combines banking fraud with advanced spyware capabilities. One of its distinctive features is the ability to borrow an internet connection from nearby infected devices when the original device lacks connectivity.

Understanding the Threat of Manic Malware

Identified by ThreatFabric’s Mobile Threat Intelligence team, Manic is positioned at the crossroads of Android banking trojans and mobile spyware. Unlike traditional malware, Manic offers its operators a comprehensive fraud toolkit, including reading a victim’s PIN, observing live screen activities, hijacking banking sessions, and extracting files, messages, and location data.

Research indicates that Manic’s infrastructure dates back to February 2026, with rapid developments seen by mid-year. This advanced version demonstrates improved anti-analysis defenses and in-memory code loading, making it a formidable threat.

Targeted Applications and Geographic Focus

Currently, Manic targets 169 applications, including banks, government identity portals, payment services, cryptocurrency wallets, and messaging platforms. The primary focus is Ukraine, targeting national banks and eID services. However, its reach extends to Russia, Poland, Germany, the Czech Republic, Slovakia, and the UK, as well as international fintech and crypto platforms.

This diverse target list suggests that the operators aim not only for financial theft but also for insights into victims’ communications, including government and military messaging apps.

Innovative Techniques and Data Exfiltration

Unlike most banking trojans that use overlay attacks, Manic employs a different strategy by using a transparent layer over the numeric keypad of genuine banking apps to record PIN entries. These inputs are then replayed to the real app using Android’s Accessibility service, allowing transactions to proceed while logging the PIN.

Manic’s standout feature is its method of data exfiltration. When direct communication with its command-and-control server is blocked, it encrypts and stores data locally, seeking another infected device nearby with internet access. This secondary device then relays the data, creating a mesh network for data transfer, which complicates data containment efforts.

Security Implications and Recommendations

The combination of stealthy PIN capture, comprehensive device takeover, and a robust exfiltration network makes Manic more challenging to detect and contain compared to typical banking trojans. ThreatFabric’s continued monitoring of this malware, alongside other threats like WindRelay NFC and Herodotus trojans, highlights a trend of integrating multiple fraud techniques into single platforms.

To safeguard against such threats, it is crucial to avoid sideloading APKs from unofficial sources, scrutinize apps requesting Accessibility permissions, and keep Google Play Protect active. These steps can help mitigate the risks posed by Manic and similar malware families.

Cyber Security News Tags:Android malware, banking security, banking trojan, cyber threat, Cybersecurity, data exfiltration, data relay, device takeover, malware relay, Manic malware, mobile security, mobile spyware, peer devices, PIN theft, ThreatFabric

Post navigation

Previous Post: Malicious Rust Crates Removed After Supply Chain Attack
Next Post: CDN Tsunami Threat: HTTP/3 Amplification in Focus

Related Posts

Hackers Exploit MLflow SSRF Flaw in Active Attacks Hackers Exploit MLflow SSRF Flaw in Active Attacks Cyber Security News
North Korean APT Hackers Attacking Ukrainian Government Agencies to Steal Login Credentials North Korean APT Hackers Attacking Ukrainian Government Agencies to Steal Login Credentials Cyber Security News
Aembit Partners with Snowflake for AI Security Enhancement Aembit Partners with Snowflake for AI Security Enhancement Cyber Security News
LexisNexis Breach Exposes Data from AWS Servers LexisNexis Breach Exposes Data from AWS Servers Cyber Security News
ClickUp’s API Key Leak Exposes Fortune 500 Emails ClickUp’s API Key Leak Exposes Fortune 500 Emails Cyber Security News
Hackers Exploit AI Token Jacking for Major API Key Theft Hackers Exploit AI Token Jacking for Major API Key Theft Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CDN Tsunami Threat: HTTP/3 Amplification in Focus
  • New Android Malware Manic Exploits Banking Security
  • Malicious Rust Crates Removed After Supply Chain Attack
  • Microsoft Defender Driver Exploitation Risks Uncovered
  • Addressing Shady AI: A Growing Governance Challenge

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CDN Tsunami Threat: HTTP/3 Amplification in Focus
  • New Android Malware Manic Exploits Banking Security
  • Malicious Rust Crates Removed After Supply Chain Attack
  • Microsoft Defender Driver Exploitation Risks Uncovered
  • Addressing Shady AI: A Growing Governance Challenge

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark