Manic Android malware targets banking, government ID, crypto, and 2FA apps and can relay stolen data through nearby infected phones

A newly detailed Android malware family called Manic is targeting users in Europe, especially Ukraine, to steal banking, government identity, cryptocurrency, messaging, and authentication data. ThreatFabric says the malware has been active since at least February 2026 and abuses Android Accessibility plus transparent keypad overlays to capture PINs, passwords, SMS codes, recovery phrases, files, notifications, location, and screen activity. It also supports remote control via WebRTC and can exfiltrate data through nearby infected devices over Wi-Fi Direct, Bluetooth, and Bluetooth Low Energy when a phone cannot reach its command server.
Why it matters: This threatens consumers, government users, and financial targets even when infected phones are intermittently offline, making detection and containment harder. Android users should avoid sideloaded APKs, be extremely cautious with Accessibility permission requests, and scan devices with Play Protect or mobile security tools.

Sources

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
Eduard Kovacs 2026.08.22 87% relevant
This article adds broader reporting on Manic, including that ThreatFabric says it targets Ukrainian banks, government services, messaging apps, Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused messaging apps, while reiterating its offline Wi‑Fi Direct/Bluetooth mesh relay capability.
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
info@thehackernews.com (The Hacker News) 2026.08.20 99% relevant
This article appears to be another report on the same Manic Android malware campaign, specifically emphasizing the Bluetooth-style relay capability that lets infected phones exfiltrate data from devices that are offline by passing it through nearby compromised devices.
New Manic Android malware can exfiltrate data through nearby devices
Bill Toulas 2026.08.20 100% relevant
This article appears to be the first tracked report establishing Manic as a distinct Android malware campaign with a novel nearby-device relay exfiltration mechanism and broad app targeting.
← Back to all stories