Manic Android Malware Steals Data From Offline Phones
A sophisticated new Android malware strain codenamed Manic has emerged as one of the most dangerous mobile threats of 2026, combining banking trojan capabilities with advanced spyware features and a groundbreaking technique that allows it to exfiltrate data from devices even when they are offline. Discovered by Dutch cybersecurity firm ThreatFabric, this malware represents a troubling evolution in the mobile threat landscape, blurring the lines between financial fraud and full-scale surveillance.
What Makes Manic Different From Other Android Malware
Android malware is not new, but Manic introduces capabilities that security researchers have never seen combined in a single package. The malware targets 169 package IDs associated with banks, peer-to-peer payment services, cryptocurrency wallets, messaging apps, government identity services, and authenticators across Ukraine, Russia, Central and Western Europe, and the United Kingdom.
What sets Manic apart is its novel Wi-Fi mesh relay mechanism. When an infected device cannot connect to the attacker’s command-and-control servers — perhaps because the user has disabled internet access or is on a restricted network — the malware can relay stolen data through another infected device in close physical proximity that does have internet access. This store-and-forward technique means that even air-gapped or offline phones are not safe if there is another compromised device nearby.
Key Capabilities of the Manic Malware
- Keypad interception: Captures passwords, one-time codes, and crypto recovery phrases by overlaying transparent elements on top of legitimate keypads
- UI keylogger: Uses Android accessibility services to classify and record text input, identifying which app is being used and whether it is on the target list
- Remote device control: Monitors the screen and interacts with the device over a WebRTC session in real time
- Location tracking: Records coordinates and timestamps, forcibly enabling location services if they are disabled
- Data exfiltration: Exports contacts, call history, SMS messages, notifications, and installed app lists
- SMS manipulation: Can send SMS messages to attacker-specified numbers with custom text content
- Persistence mechanisms: Hides from the launcher and uses background workers, alarms, and accessibility services to maintain C2 communication every 10 to 15 minutes
How Manic Infects Devices
Manic is distributed through phishing sites and dropper apps that impersonate legitimate utility applications. The malware has been observed using package names that mimic trusted brands, including伪装 packages such as tech.intel.dialer.updater, org.honor.secure.helper, org.lenovo.storage.processor, and dev.huawei.media.helper. By adopting names that reference well-known manufacturers like Intel, Honor, Lenovo, and Huawei, the malware aims to appear legitimate to unsuspecting users.
The infection chain begins when a user is tricked into downloading what appears to be a system utility or dialer update. Once installed, the wrapper application deploys the implant, which then requests accessibility service permissions. These permissions are the cornerstone of Manic’s power, granting the malware the ability to read screen contents, interact with other apps, and capture user input without detection.
The PIN Capture Technique
One of the most alarming features of Manic is its ability to capture PIN codes without displaying a fake banking interface. The malware serves a transparent overlay atop the legitimate numeric keypad in targeted applications. When a user taps the overlay, the malware records the exact tap position and nearby UI elements. It then briefly disables touch interception and replicates the tap on the actual keypad at the same position using the accessibility services API.
This means the targeted application functions normally from the user’s perspective, while the attacker silently captures the PIN. The victim sees nothing unusual, enters their credentials, and completes their transaction — completely unaware that every digit has been recorded by malware running in the background.
Timeline of Manic’s Development
ThreatFabric’s investigation traced Manic’s activity back to February 2026, when the first domain was registered using a fabricated persona. The development timeline reveals a methodical and well-resourced operation:
- February 2026: First domain registered with fake identity
- May 2026: First wrapper using a booking app lure and initial implant appears
- June to mid-July 2026: Development paused, possibly for restructuring
- July 13, 2026: Second deployment with stronger anti-analysis checks and lock screen phishing capabilities
- July 24-28, 2026: Command-and-control panel and API go live
Who Is Behind Manic
The targeting pattern provides clues about the threat actor’s motivations and possible affiliations. The heavy focus on Ukrainian banks, government services, and military communications apps suggests a potential nexus with the ongoing geopolitical conflict in the region. However, the malware also targets Russian financial institutions, which complicates attribution. The inclusion of European fintech services and cryptocurrency platforms indicates that the operators are also financially motivated, not purely serving state-sponsored objectives.
ThreatFabric described Manic as sitting at the intersection of Android banking malware and mobile spyware. This dual nature — combining financial fraud capabilities with broad surveillance and device control — makes it particularly dangerous for both individual users and organizations.
How to Protect Yourself Against Advanced Mobile Malware
As malware like Manic grows more sophisticated, individuals and organizations must adopt a multi-layered defense strategy:
For Individual Users
- Only install apps from official sources: Google Play Store and manufacturer-approved app stores have security scanning, though threats can still slip through
- Scrutinize accessibility permissions: No legitimate utility app needs accessibility services. If a dialer or storage helper requests this permission, treat it as a red flag
- Keep your device updated: Security patches address vulnerabilities that malware exploits to gain elevated access
- Use mobile security software: Reputable mobile security apps can detect known malware families and suspicious behavior patterns
- Monitor app behavior: If your phone exhibits unexpected battery drain, data usage spikes, or unusual background activity, investigate immediately
For Organizations
- Deploy Mobile Device Management (MDM): Enforce app installation policies and monitor device compliance across your fleet
- Implement app allowlisting: Restrict employees to approved applications, especially for devices that access corporate resources
- Use mobile threat defense solutions: Enterprise-grade mobile security platforms can detect and block sophisticated threats like Manic
- Educate employees: Regular security awareness training should cover mobile-specific threats, including phishing and fake app installations
- Segregate sensitive communications: Consider dedicated devices or secure communication platforms for sensitive organizational communications
The Broader Implications for 2026
Manic is part of a broader trend in 2026 where malware developers are incorporating increasingly novel techniques to evade detection and maintain persistence. The Wi-Fi mesh relay mechanism is particularly concerning because it undermines one of the traditional assumptions in mobile security — that taking a device offline can prevent data exfiltration. This technique could inspire other malware families to adopt similar approaches, creating a new category of mesh-capable mobile threats.
The blending of banking trojan and spyware functionality also signals a shift in the threat landscape. Where malware families once specialized in either financial fraud or surveillance, the most dangerous new strains now do both. This means that a single infection can result in both immediate financial losses and long-term compromise of personal and organizational security.
According to recent data from Kaspersky, mobile malware detections remain significant globally, with over 15,000 mobile malware samples identified in Indonesia alone in Q1 2026. The combination of widespread mobile adoption, increasing sophistication of threats like Manic, and the growing intersection of geopolitical conflict and cybercrime creates a challenging environment for defenders.
Conclusion
The Manic Android malware represents a new frontier in mobile threats — one where offline devices are not safe, PIN codes are captured invisibly, and a single infection enables both financial theft and pervasive surveillance. As threat actors continue to innovate, the security community must respond with equal creativity. The discovery of Manic should serve as a wake-up call for mobile users and organizations alike: the threat is evolving, and our defenses must evolve with it.
Staying informed about emerging threats, maintaining vigilance with app permissions, and investing in robust mobile security solutions are no longer optional — they are essential practices for navigating the increasingly hostile mobile threat landscape of 2026.
Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous
Discover more from QUE.com
Subscribe to get the latest posts sent to your email.
