Manic Android Malware Steals Data Through Nearby Devices

Manic Android Malware Steals Data Through Nearby Devices

A sophisticated new Android malware strain dubbed Manic has emerged as one of the most dangerous mobile threats of 2026, combining banking trojan capabilities with advanced spyware features and a novel data exfiltration technique that works even when the infected device has no internet connection. Discovered by Dutch security firm ThreatFabric, Manic represents a significant evolution in mobile malware — blurring the lines between financial fraud tools and full-scale surveillance operations.

What Makes Manic Different

Most Android malware relies on a persistent internet connection to relay stolen data back to command-and-control servers. Manic breaks this assumption entirely. It introduces a store-and-forward relay mechanism that allows an infected device to pass stolen data through nearby compromised devices using Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT connections. This means that even if you disconnect your phone from the internet, the malware can still exfiltrate your data by using another infected Android device in close physical proximity as a gateway.

The relay supports multi-hop routing, with each queued data packet configured for a maximum of four relay hops by default. If no peer device is found, the stolen data is encrypted and stored in a local queue, then retried later. This mesh networking approach makes Manic extraordinarily resilient — traditional defenses like disconnecting from Wi-Fi or mobile data are no longer sufficient to stop data theft.

Scope of the Attack

Manic targets an alarming 169 Android applications spanning multiple categories:

  • Banking and financial institutions across Ukraine, Russia, Central and Western Europe, and the United Kingdom
  • Peer-to-peer payment and Buy Now, Pay Later services
  • Cryptocurrency wallets and exchanges
  • Government and electronic identity services
  • Messaging applications, including commercial and military-focused platforms
  • Email clients and authentication apps
  • Web browsers

The breadth of targeting suggests that Manic was designed for both financial fraud and intelligence gathering. Its ability to track location, monitor notifications, collect files, and conduct remote device surveillance makes it a dual-purpose tool suitable for both cybercriminals and state-sponsored actors.

How Manic Captures Your PIN Codes

One of the most technically sophisticated aspects of Manic is its PIN interception technique. Rather than displaying a fake banking interface — a common tactic that can alert security-conscious users — Manic deploys a transparent overlay on top of the legitimate numeric keypad within a targeted app. When the user taps the keypad, the malware records the exact tap position and the nearby UI element. It then briefly disables touch interception and replicates the tap on the actual keypad using Android’s accessibility services API.

The result is chilling: the targeted banking or payment app functions completely normally, and the user has no idea their PIN has been captured. The threat actor obtains the PIN code without ever showing a fake interface, making detection by the victim nearly impossible.

Additional Malware Capabilities

Beyond PIN capture and mesh relay exfiltration, Manic includes a comprehensive toolkit for device takeover:

  • UI keylogger using accessibility services to classify and record all text input along with the app being used
  • WebRTC remote control allowing attackers to monitor the screen and interact with the device in real time
  • SMS interception and the ability to send SMS to attacker-supplied numbers
  • Contact, call history, and notification export for comprehensive data harvesting
  • Screenshot capture and location tracking with timestamp data
  • Google Play Protect disabling through UI automation to prevent detection
  • Lock screen control through accessibility service manipulation
  • File deletion to cover tracks after data exfiltration

Persistence is maintained through background workers, alarms, and the accessibility and notification services, which periodically execute every 10 to 15 minutes to maintain command-and-control communication, process commands, upload queued data, and synchronize the offline mesh network.

The Broader Trend: AI Brand Impersonation Malware

Manic is part of a broader escalation in malware delivery techniques observed throughout 2026. Security researchers at Sophos, Microsoft, and Help Net Security have documented a sharp rise in threat actors impersonating popular AI brands — including ChatGPT, Claude, Gemini, and Microsoft Copilot — to distribute infostealers and backdoors. Attackers are creating fake AI websites, hijacking search engine results through SEO poisoning, and even abusing legitimate AI platforms like claude.ai shared chats to deliver malware through fake “verification” or “security check” prompts.

This trend exploits the rapid public adoption of AI tools. Users who would normally be cautious about downloading unknown software are more likely to trust an installer branded as a ChatGPT desktop client or a Claude code assistant. The malware delivered through these vectors typically includes infostealers that harvest browser credentials, cryptocurrency wallets, and session tokens — providing attackers with everything they need to compromise online accounts at scale.

How to Protect Yourself

Defending against threats like Manic and AI-impersonation malware requires a multi-layered approach:

  • Only install apps from Google Play: Google has confirmed that no apps containing Manic have been found on Google Play, and Google Play Protect automatically protects against known variants. Sideloading APKs from unknown sources remains the primary infection vector.
  • Review accessibility permissions carefully: Manic and similar malware abuse Android’s accessibility services. No legitimate utility app should request accessibility permissions unless it is explicitly designed for users with disabilities.
  • Verify AI tool downloads: Always download AI tools from official websites. Be suspicious of Google Ads promoting AI software, and verify the domain URL before installing anything.
  • Keep Google Play Protect enabled: Never disable Play Protect, and be wary of any app that asks you to do so through UI automation prompts.
  • Monitor for unusual Bluetooth or Wi-Fi activity: Since Manic uses local mesh networking, unexpected Wi-Fi Direct or Bluetooth connections on your device could indicate compromise.
  • Use multi-factor authentication: Even if credentials are stolen, MFA provides an additional layer of protection for your financial and email accounts.
  • Keep your device updated: Android security patches address the vulnerabilities that malware exploits to gain elevated access. Running the latest security update reduces your attack surface significantly.

The Road Ahead

The emergence of Manic signals a new era in mobile malware — one where threat actors are willing to invest significant development effort into creating resilient, multi-purpose tools that can evade both user detection and network-level defenses. The combination of banking fraud, surveillance capabilities, and mesh-based exfiltration represents a convergence that security teams have long anticipated but rarely seen executed at this level of sophistication.

As AI brand impersonation continues to grow as a primary delivery mechanism, the line between trusted technology and malicious exploitation grows thinner. Organizations and individuals alike must adopt a posture of zero trust when it comes to software downloads, even when they appear to come from recognizable AI brands. The malware landscape of 2026 demands vigilance, education, and proactive defense at every level.


Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading