The Manic Android malware can steal sensitive data from compromised phones and send it through nearby infected devices when it cannot reach its command-and-control server directly. The threat combines banking fraud, spyware features and remote-control tools in one Android package.

Researchers say Manic has operated since at least February. It targets users across several European countries, with Ukrainian banking and government-related apps appearing to be a major focus.

Manic Android malware targets financial and government apps

The malware targets at least 169 applications, including banking, payment, government eID, cryptocurrency wallet, messaging and authenticator apps. It also targets services used in Central and Western Europe, the UK, Russia and Ukraine.

ThreatFabric researchers found that Manic uses transparent overlays on the numeric keypads of legitimate apps. These overlays record a victim’s taps while the genuine app continues to work normally in the background.

The malware then uses Android Accessibility services to reproduce the captured input. This approach lets attackers collect data without immediately alerting the victim that something has changed.

Malware captures PINs, passwords and SMS codes

Once Manic gains Accessibility and notification permissions, it can collect a wide range of information from the device. This includes lock-screen PINs and passwords, incoming notifications, SMS messages, files and location data.

The malware can also monitor the device screen and give its operators remote access through WebRTC sessions. In addition, it sorts stolen information into categories before saving it.

Researchers describe the Accessibility service as a user-interface keylogger. It can distinguish between lock-screen input, possible recovery phrases, SMS verification codes, passwords, email logins, longer messages and ordinary text.

That classification makes the stolen data easier for criminals to use. For example, attackers can quickly identify a one-time banking code or a cryptocurrency recovery phrase among a larger volume of collected information.

Nearby infected phones can relay stolen data

Manic has an unusual fallback system for data theft. If the infected phone cannot contact its command-and-control server, it can encrypt the collected information and pass it to another nearby compromised device.

The malware first attempts to use an existing Wi-Fi Direct connection. It can then look for Bluetooth and Bluetooth Low Energy devices with internet access. If needed, it can relay data across several infected devices before it reaches the attackers’ infrastructure.

By default, the malware can use up to four relay hops. This means an offline infected phone may still leak data if another compromised device sits within Wi-Fi or Bluetooth range.

Researchers observed expanding Manic infrastructure

The exact infection method remains unknown. However, researchers observed a wrapper used to deliver the main malware payload in late May.

The attackers expanded their infrastructure over the following months. In July, researchers identified an updated wrapper with stronger anti-analysis features and in-memory DEX loading. They also observed a new control panel and API.

These changes suggest that the operators continue to develop the campaign and improve its ability to avoid detection.

Conclusion

The Manic Android malware poses a serious risk because it combines banking fraud, surveillance and remote access with a resilient data-relay feature. Android users should avoid APK downloads from unofficial sources, limit Accessibility permissions to trusted apps and run regular Play Protect scans.


0 responses to “Manic Android Malware Can Exfiltrate Data Through Nearby Devices”