Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
ID: 1129f4ad-410e-52bf-b77d-f63ce3b3eef5
STIX ID: report--1129f4ad-410e-52bf-b77d-f63ce3b3eef5
Feed Name: The Hacker News
Manic is a sophisticated Android malware family observed targeting Ukrainian banks, government and identity services, messaging apps, Russian and European financial institutions, global fintech/cryptocurrency services, and military-focused communications. Combining banking-fraud features with spyware capabilities, Manic abuses Android accessibility and notification services, overlays, UI keylogging, remote control via WebRTC, and a novel store-and-forward Wi‑Fi/Bluetooth/BLE mesh relay to exfiltrate data through nearby compromised devices; it is distributed via phishing sites and dropper apps, with active development and deployments observed between February and July 2026 and several APK package names and behavioral IOCs identified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
