Protect.Computer
NEWS

Manic Android Malware Steals Data via Nearby Infected Devices

· 1 min read · Malicious byte Data hijack
Manic Android Malware Steals Data via Nearby Infected Devices

A newly documented Android banking trojan called Manic has an unusual survival trick: if the malware can’t reach its command-and-control server, it encrypts the stolen data and passes it through nearby compromised devices over Wi-Fi Direct or Bluetooth, relaying it up to four hops until it finds a phone with internet access. Mobile security company ThreatFabric discovered the malware active since at least February, primarily targeting users in Ukraine and other European countries, though its reach covers 169 apps across banking, government ID, payment, crypto wallet, messaging, and authenticator categories.

Beyond the mesh-relay trick, Manic is a capable banking trojan in its own right. After tricking users into granting Accessibility and notification permissions, it operates as a keylogger that classifies every tap it captures — distinguishing lock-screen PINs, seed phrases, SMS codes, and passwords before sending each to a different data bucket. It overlays invisible grids on numeric keypads so the legitimate app keeps working normally while every digit is recorded. Operators can also open real-time remote-control sessions via WebRTC. The mesh fallback is what makes Manic unusual: by offloading exfiltration to the nearest infected phone in range, operators can retrieve data from devices that are temporarily offline, in flight mode, or on networks that block outbound connections to known C2 infrastructure.

How to check if you’re affected

Affected devices are Android phones in Ukraine and across Europe, though the target app list includes major banking and crypto apps available globally. Check for unexpected Accessibility service entries: go to Settings → Accessibility → Installed Apps and look for anything you don’t recognise. A legitimate banking app will never appear in that list. Also review which apps have notification access (Settings → Apps → Special app access → Notification access). If either list contains an unfamiliar entry, revoke it immediately, run a mobile security scan, and change your banking and email passwords from a separate clean device. Manic is distributed via sideloaded APKs, not the Play Store — only install apps from Google Play.

Sources

Related reading