discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

New Manic Android malware can exfiltrate data through nearby devices

A new Android malware named Manic targets users in multiple European countries, combining spyware, banking fraud, and remote control capabilities. It captures user taps, intercepts notifications and SMS messages, collects files and location data, and provides remote contr…

By Bill Toulas·Aug 20·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

New Manic Android malware can exfiltrate data through nearby devices
Image: bleepingcomputer.com

The Manic malware uses transparent overlays on numeric keypads of legitimate applications to capture victims' taps and reproduce them through Android Accessibility. It also captures the lock PIN/password, intercepts notifications and SMS messages, collects files and location data, and provides remote control to operators.

Why it matters

This story matters to someone following Security because it highlights a new Android malware that can exfiltrate data through nearby devices, compromising user privacy and security.

Imagine someone is watching what you type on your phone's keypad. They can see your passwords, PINs, and even your messages. This malware is like a sneaky spy that can do all that and more, even when your phone is offline. It's like having a bad neighbor who always knows what you're doing.

Analysis

Manic Malware Overview

The Manic malware is a new Android threat that has been active since at least February. It targets users in multiple European countries, including the U.K. and Russia, with a primary focus on banking and government/eID applications in Ukraine. The malware combines spyware, banking fraud, and remote control capabilities, making it a significant concern for Android users.

Data Exfiltration Mechanism

The Manic malware uses an unusual data exfiltration mechanism that kicks in when a compromised device cannot reach the command-and-control (C2) server. In this scenario, the malware encrypts and transfers the captured data via nearby compromised devices over Wi-Fi Direct or Bluetooth connections. This mechanism allows data exfiltration even from offline devices, as long as another infected device is within WiFi or Bluetooth range.

Attack Chain

The Manic malware authors implemented an attack chain that involves the following steps:

  1. The malware uses transparent overlays on the numeric keypads of legitimate applications to capture victims' taps and reproduce them through Android Accessibility.
  2. It captures the lock PIN/password, intercepts notifications and SMS messages, collects files and location data, and provides remote control to operators via WebRTC sessions.
  3. The captured information is categorized by type, making the data more readily exploitable for the malware operators.

Prevention and Mitigation

Android users are advised to avoid downloading APKs from obscure sources and unofficial portals, deny Accessibility permissions unless required by a trusted application, and regularly run Play Protect scans to detect and remove known malware. Once attackers have valid credentials, only 37% of their actions are blocked, highlighting the need for robust security measures.

Key points

  • The Manic malware targets users in multiple European countries, combining spyware, banking fraud, and remote control capabilities.
  • It captures user taps, intercepts notifications and SMS messages, collects files and location data, and provides remote control to operators.
  • The malware uses an unusual data exfiltration mechanism that kicks in when a compromised device cannot reach the C2 server.
  • Android users are advised to avoid downloading APKs from obscure sources and unofficial portals, deny Accessibility permissions unless required by a trusted application, and regularly run Play Protect scans.
The Upside

If this development plays out positively, Android users may see improved security measures implemented by Google, such as enhanced Play Protect scans and more robust Accessibility permission controls. This could lead to a decrease in malware infections and a safer overall Android experience.

The Downside

The realistic downside risks of this malware include the potential for widespread data breaches, compromised user privacy, and financial losses due to banking fraud. If the malware is not effectively mitigated, it could lead to a significant increase in Android security threats.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagsandroidmalwaresecuritydata-exfiltrationspywarebanking-fraudremote-control

Author

Bill Toulas

Intelligence analysis by

Llama

Published

Aug 20, 2026

Source

bleepingcomputer.com

Share

Topics

androidmalwaresecuritydata-exfiltrationspywarebanking-fraudremote-control

Related

More from this desk

Aug 20·bleepingcomputer.com

Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.

Aug 20·bleepingcomputer.com

CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical MLflow vulnerability. This vulnerability can be used by attackers without privileges to remotely access internal services or cloud metadata…

Aug 20·thehackernews.com

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrumen…

Aug 20·bleepingcomputer.com

Critical Zimbra RCE flaw now actively exploited in attacks

A critical vulnerability in Zimbra Collaboration Suite (ZCS) is being actively exploited by attackers. The flaw, tracked as CVE-2026-73570, allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring com…