A new Android malware, dubbed Manic, has been identified with a unique data exfiltration method that utilizes nearby infected devices when a direct connection to its command-and-control (C2) server is unavailable. This sophisticated malware has been active since at least February and combines capabilities for spyware, banking fraud, and remote control.
Manic primarily targets users in Ukraine, but its reach extends to other European countries, including the U.K., and Russia. It is designed to compromise at least 169 different applications, encompassing banking, government/eID, payment, cryptocurrency wallet, messaging, and two-factor authentication (2FA) services.
Upon gaining Android Accessibility and notification access permissions, Manic can capture a victim's lock PIN or password, intercept SMS messages and notifications, collect location data and files, and monitor the device screen. It also allows remote operators to control the compromised device via WebRTC sessions. The malware categorizes the stolen information, distinguishing between lock-screen input, recovery phrases, four-to-six-digit SMS codes, passwords, email logins, long messages, and general text, making the data more readily exploitable.
A key feature of Manic is its use of transparent overlays on legitimate application keypads to capture user taps. This method allows the malware to reproduce these taps through Android Accessibility, ensuring the legitimate applications continue to function normally while user input is recorded.
The most notable aspect of Manic is its fallback data exfiltration mechanism. If a compromised device cannot establish a connection with its C2 server, the malware encrypts the collected data and attempts to transfer it via nearby infected devices using Wi-Fi Direct or Bluetooth. The malware first tries to use an existing Wi-Fi Direct peer, then queries Bluetooth and Bluetooth Low Energy (BLE) peers to check for internet connectivity. It can also establish multi-hop routes, with new data items configured to traverse a maximum of four relay hops by default. This enables data exfiltration even from offline devices, provided another infected device is within Wi-Fi or Bluetooth range.
The exact initial infection vector for Manic remains unconfirmed. However, researchers observed in late May the use of a wrapper to deliver the main payload, followed by an expansion of the malware's infrastructure. By July, an updated wrapper with enhanced anti-analysis checks and in-memory DEX loading was noted in attacks, alongside the deployment of a new panel and API.
Android users are advised to exercise caution by avoiding the download of APKs from unofficial or obscure sources. They should also be wary of granting Accessibility permissions unless absolutely necessary for a trusted application and regularly utilize Play Protect scans to detect and remove known malware.






