LIVE · cybersecurity feed
Live wire
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsCritical Elementor Pro bug exposes WordPress sites to RCE attacksThe push to designate AI as the next critical infrastructure sectorCritical Zimbra RCE flaw now actively exploited in attacksExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerCVE-2026-19478 · Critical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-32475 · Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
malwarehigh

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]

zeroday.news ·

A new Android malware, dubbed Manic, has been identified by ThreatFabric's Mobile Threat Intelligence team, active since at least February 2026. The malware, which is still under development as of July, combines features of banking malware and mobile spyware, enabling financial fraud, surveillance, and device control.

Manic's targeting is heavily focused on Ukraine, including Ukrainian banks, government and identity services, and messaging applications. It also extends to Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications. The malware monitors 169 different Android applications, encompassing banking and payment apps across several European countries, government and eID services, crypto exchanges and wallets, two-factor authentication tools, messaging apps, browsers, and email clients. This broad targeting allows attackers to track a victim’s finances, communications, location, and files from a single compromised device.

Initial infrastructure registrations for Manic were observed in February 2026, with development and production services appearing in late March and April. By July, an updated build incorporated enhanced anti-analysis checks, in-memory DEX loading, and a "lock-secret phishing" technique. This technique presents a fake prompt before the legitimate lock screen to extract the device's PIN or pattern.

Upon installation, Manic requests Accessibility and notification access. It then leverages the Accessibility service as a UI keylogger, classifying captured input before logging it. This includes lock-screen input, recovery phrase candidates, four-to-six-digit SMS codes, passwords, long messages, email logins, and ordinary text. Each log record contains the app name and package, the captured text, a timestamp, whether the input was autofilled or manually entered, and whether the app is on Manic's target list.

The malware's PIN theft method differs from typical banking overlays. When a numeric keypad is detected in a targeted application, Manic places an invisible layer over the keys, recording each tap. It then briefly passes the tap to the real keypad via Android’s Accessibility features, allowing the banking app to function normally while the PIN is captured. An "autoEnterPin" function can also attempt to enter a stored PIN or pattern on the Android lock screen, providing attackers with the ability to unlock the device remotely using a previously captured PIN.

A particularly distinctive feature of Manic is its offline relay mechanism. It uses a store-and-forward system to exfiltrate data even when the infected device lacks a direct connection to the command-and-control (C2) server. Collected files and command results are encrypted with AES-GCM and stored in a local queue. The malware then searches for other nearby infected devices via Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT, using them as relays to reach the C2 infrastructure. This system supports chains of up to four relay hops, meaning that cutting an infected phone off from the internet does not prevent data exfiltration as long as another infected device is within radio range.

Manic also grants attackers remote control of the device through WebRTC, enabling them to view the screen and interact with it using Android’s Accessibility features. It can conceal its activities with black screens, fake screens, or fake update messages, and can also hide permission requests. The July version further enhances stealth by removing itself from the device’s app launcher, keeping it out of the normal app list and allowing activation through its wrapper or a deep link.

The combination of credential theft, live screen monitoring, authentication interception, device takeover, and an offline exfiltration path makes Manic a comprehensive threat. For defenders, monitoring for unusual Accessibility service grants and unexpected Bluetooth or Wi-Fi Direct connections from phones not actively transferring files are practical starting points for detection. Manic is described as an evolving Android fraud platform designed for Device Takeover (DTO).

malwarefinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.

ai

Detailed Timeline of OpenAI’s Cyberattack on Hugging Face

OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.

vulnerability

N-able Bug Exposes Password Vault Master Keys

The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?

aicritical

NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs

NSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure sectors. Five U.S. federal agencies issued a joint advisory this week warning of an active hacking campaign against Siemens S7 Series programmable logic controllers. The advisory, CISA AA26-231A, is co-signed by NSA, FBI, DOE, and EPA […]

security

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears

The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.