A new Android malware strain named Manic is targeting users in multiple European countries, with a fallback mechanism that can exfiltrate data through nearby infected devices. The malware, active since at least February, combines spyware, banking fraud, and remote control capabilities, according to mobile security firm ThreatFabric. It targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA applications, with users in Ukraine being the primary focus.

ThreatFabric reports that Manic uses transparent overlays on numeric keypads of legitimate apps to capture victims' taps, reproducing them through Android Accessibility so the legitimate applications continue functioning normally. Once it obtains Accessibility and notification access permissions, the malware can capture lock screen PINs or passwords, intercept notifications and SMS messages, collect files and location data, monitor the screen, and provide remote control to operators via WebRTC sessions. The captured information is categorized by type, making the data more readily exploitable for the operators.

According to ThreatFabric, Manic uses its Accessibility service as a UI keylogger, classifying captured text before recording it, distinguishing lock-screen input, recovery-phrase candidates, four-to-six-digit SMS codes, passwords, long messages, email logins, and ordinary text. The malware authors implemented an unusual data exfiltration mechanism that activates when a compromised device cannot reach its command-and-control (C2) server. The researchers say data is encrypted and transferred via nearby compromised devices over Wi-Fi Direct or Bluetooth connections.

The malware first attempts to use an established Wi-Fi Direct peer, then queries Bluetooth and BLE peers to determine whether they have internet connectivity, according to ThreatFabric. If necessary, Manic can also use multi-hop routes, with newly queued items configured for a maximum of four relay hops by default. This mechanism allows data exfiltration even from offline devices, as long as another infected device is within Wi-Fi or Bluetooth range.

ThreatFabric says the malware targets applications used across Central and Western Europe, including the U.K., as well as Russia. However, its primary focus appears to be banking and government/eID applications in Ukraine, along with global fintech and cryptocurrency services. The exact infection vector remains unknown, but researchers observed in late May the use of a wrapper that delivered the main payload to victims, followed by an expansion of existing infrastructure in the months that followed.

In July, an updated wrapper with stronger anti-analysis checks and in-memory DEX loading was observed in attacks, and a new panel and API also rolled out. For U.S. users, the threat is indirect but notable given the global fintech and crypto targets included in the malware’s scope. Android users are advised to avoid downloading APKs from obscure sources and unofficial portals, deny Accessibility permissions unless required by a trusted application, and regularly run Play Protect scans to detect and remove known malware.

More cybersecurity news from TechManNews.