LIVE · cybersecurity feed
Live wire
Critical Zimbra RCE flaw now actively exploited in attacksExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerCVE-2026-19478 · Critical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-32475 · Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2024-39943 · Operation CameraSwarm Compromised 14,000+ Dahua CamerasCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
malware

New Manic Android malware can exfiltrate data through nearby devices

A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]

zeroday.news ·

A new Android malware, dubbed Manic, has been identified with a unique data exfiltration method that utilizes nearby infected devices when a direct connection to its command-and-control (C2) server is unavailable. This sophisticated malware has been active since at least February and combines capabilities for spyware, banking fraud, and remote control.

Manic primarily targets users in Ukraine, but its reach extends to other European countries, including the U.K., and Russia. It is designed to compromise at least 169 different applications, encompassing banking, government/eID, payment, cryptocurrency wallet, messaging, and two-factor authentication (2FA) services.

Upon gaining Android Accessibility and notification access permissions, Manic can capture a victim's lock PIN or password, intercept SMS messages and notifications, collect location data and files, and monitor the device screen. It also allows remote operators to control the compromised device via WebRTC sessions. The malware categorizes the stolen information, distinguishing between lock-screen input, recovery phrases, four-to-six-digit SMS codes, passwords, email logins, long messages, and general text, making the data more readily exploitable.

A key feature of Manic is its use of transparent overlays on legitimate application keypads to capture user taps. This method allows the malware to reproduce these taps through Android Accessibility, ensuring the legitimate applications continue to function normally while user input is recorded.

The most notable aspect of Manic is its fallback data exfiltration mechanism. If a compromised device cannot establish a connection with its C2 server, the malware encrypts the collected data and attempts to transfer it via nearby infected devices using Wi-Fi Direct or Bluetooth. The malware first tries to use an existing Wi-Fi Direct peer, then queries Bluetooth and Bluetooth Low Energy (BLE) peers to check for internet connectivity. It can also establish multi-hop routes, with new data items configured to traverse a maximum of four relay hops by default. This enables data exfiltration even from offline devices, provided another infected device is within Wi-Fi or Bluetooth range.

The exact initial infection vector for Manic remains unconfirmed. However, researchers observed in late May the use of a wrapper to deliver the main payload, followed by an expansion of the malware's infrastructure. By July, an updated wrapper with enhanced anti-analysis checks and in-memory DEX loading was noted in attacks, alongside the deployment of a new panel and API.

Android users are advised to exercise caution by avoiding the download of APKs from unofficial or obscure sources. They should also be wary of granting Accessibility permissions unless absolutely necessary for a trusted application and regularly utilize Play Protect scans to detect and remove known malware.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Managing the cyber risk of agentic AI

Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.

ai

OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses

The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities. The post OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses appeared first on SecurityWeek.

security

Police Are Hiding Their Use of Flock Surveillance Cameras

A usage policy for Flock license plate reader cameras tells police not to talk about the cameras: When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy d

vulnerabilitycritical

Critical Zimbra RCE flaw now actively exploited in attacks

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]

phishing

Def Con Attendees Targeted by Persistent Phishing Campaign

Huntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def Con

security

US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign

The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Department unsealed a superseding indictment this week charging 17 members of the Mabna Institute, […]