logo

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

ID: 1129f4ad-410e-52bf-b77d-f63ce3b3eef5

STIX ID: report--1129f4ad-410e-52bf-b77d-f63ce3b3eef5

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-08-20

Date Updated: 2026-08-21

Author: [email protected] (The Hacker News)

...
...

Manic is a sophisticated Android malware family observed targeting Ukrainian banks, government and identity services, messaging apps, Russian and European financial institutions, global fintech/cryptocurrency services, and military-focused communications. Combining banking-fraud features with spyware capabilities, Manic abuses Android accessibility and notification services, overlays, UI keylogging, remote control via WebRTC, and a novel store-and-forward Wi‑Fi/Bluetooth/BLE mesh relay to exfiltrate data through nearby compromised devices; it is distributed via phishing sites and dropper apps, with active development and deployments observed between February and July 2026 and several APK package names and behavioral IOCs identified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.