New Manic Android malware can exfiltrate data through nearby devices
A new Android malware named Manic targets users in multiple European countries, combining spyware, banking fraud, and remote control capabilities. It captures user taps, intercepts notifications and SMS messages, collects files and location data, and provides remote contr…
Intelligence analysis by Llama

The Manic malware uses transparent overlays on numeric keypads of legitimate applications to capture victims' taps and reproduce them through Android Accessibility. It also captures the lock PIN/password, intercepts notifications and SMS messages, collects files and location data, and provides remote control to operators.
Imagine someone is watching what you type on your phone's keypad. They can see your passwords, PINs, and even your messages. This malware is like a sneaky spy that can do all that and more, even when your phone is offline. It's like having a bad neighbor who always knows what you're doing.
Analysis
Manic Malware Overview
The Manic malware is a new Android threat that has been active since at least February. It targets users in multiple European countries, including the U.K. and Russia, with a primary focus on banking and government/eID applications in Ukraine. The malware combines spyware, banking fraud, and remote control capabilities, making it a significant concern for Android users.
Data Exfiltration Mechanism
The Manic malware uses an unusual data exfiltration mechanism that kicks in when a compromised device cannot reach the command-and-control (C2) server. In this scenario, the malware encrypts and transfers the captured data via nearby compromised devices over Wi-Fi Direct or Bluetooth connections. This mechanism allows data exfiltration even from offline devices, as long as another infected device is within WiFi or Bluetooth range.
Attack Chain
The Manic malware authors implemented an attack chain that involves the following steps:
- The malware uses transparent overlays on the numeric keypads of legitimate applications to capture victims' taps and reproduce them through Android Accessibility.
- It captures the lock PIN/password, intercepts notifications and SMS messages, collects files and location data, and provides remote control to operators via WebRTC sessions.
- The captured information is categorized by type, making the data more readily exploitable for the malware operators.
Prevention and Mitigation
Android users are advised to avoid downloading APKs from obscure sources and unofficial portals, deny Accessibility permissions unless required by a trusted application, and regularly run Play Protect scans to detect and remove known malware. Once attackers have valid credentials, only 37% of their actions are blocked, highlighting the need for robust security measures.
Key points
- The Manic malware targets users in multiple European countries, combining spyware, banking fraud, and remote control capabilities.
- It captures user taps, intercepts notifications and SMS messages, collects files and location data, and provides remote control to operators.
- The malware uses an unusual data exfiltration mechanism that kicks in when a compromised device cannot reach the C2 server.
- Android users are advised to avoid downloading APKs from obscure sources and unofficial portals, deny Accessibility permissions unless required by a trusted application, and regularly run Play Protect scans.
If this development plays out positively, Android users may see improved security measures implemented by Google, such as enhanced Play Protect scans and more robust Accessibility permission controls. This could lead to a decrease in malware infections and a safer overall Android experience.
The realistic downside risks of this malware include the potential for widespread data breaches, compromised user privacy, and financial losses due to banking fraud. If the malware is not effectively mitigated, it could lead to a significant increase in Android security threats.



