Published on August 20, 2026

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices


Severity
High

Detail

A new Android malware family named Manic has been observed targeting banking, cryptocurrency, government identity, messaging, and military-focused applications. The malware combines banking trojan and spyware capabilities with extensive device-control and surveillance features. Manic has been active since at least February 2026 and is distributed through phishing websites and malicious dropper applications disguised as legitimate utilities. The malware monitors 169 application package IDs, primarily targeting Ukrainian applications while also covering financial and messaging applications used across Russia, Europe, and the U.K.

How?

Manic abuses Android Accessibility Services and notification permissions to monitor and control infected devices. It can capture passwords, one-time codes, recovery phrases, SMS messages, notifications, contacts, call history, screenshots, installed applications, and device location.

The malware can also operate as a UI keylogger by recording text entered into targeted applications. It uses transparent overlays to capture PIN codes by recording the user’s keypad interactions while allowing the legitimate application to continue functioning normally.

Manic supports remote device monitoring and control through WebRTC and can display fake overlays and notifications, lock the device, send SMS messages, collect files, and attempt to disable Google Play Protect. Its persistence relies on background workers, alarms, Accessibility Services, and notification services to maintain C2 communication and process commands.

A notable capability of Manic is its offline data exfiltration mechanism. When an infected device cannot connect to the attacker’s C2 infrastructure, collected data is encrypted and stored locally. The malware then searches for nearby infected Android devices using Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT. If another infected device with internet access is found, the stored data is transferred to that device and forwarded to the attacker’s C2 server. Manic also supports multi-hop communication, allowing data to pass through up to four infected devices by default. This means disconnecting an infected phone from the internet does not necessarily prevent data exfiltration.

Recommendation

Organizations should implement a layered security approach to reduce the risk of Manic Android malware infections:

  • Avoid installing Android applications from unofficial sources and verify applications before installation.
  • Keep Android devices and security software updated with the latest security patches.
  • Review applications with Accessibility Services and notification access enabled and disable unnecessary permissions.
  • Monitor Android devices for suspicious applications, unexpected overlays, unusual accessibility activity, and abnormal network connections.
  • Use mobile threat defense (MTD) or EDR solutions where available to detect malicious Android applications and behavior.
  • Educate users to identify phishing websites and fake applications requesting excessive permissions.

Source

https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html