A new and highly sophisticated threat for Android has emerged, dubbed Manic, targeting a wide range of financial, government, and communications applications. According to cybersecurity firm ThreatFabric, the malware is primarily focused on Ukrainian organizations, while also targeting Russian and European banks, fintech services, cryptocurrency platforms, and communications applications military.

Its capabilities far exceed those of typical banking malware. Manic combines financial fraud functionality with spyware features, allowing its operator to monitor the device, collect data, and perform remote actions.
169 applications in the spotlight
ThreatFabric's analysis revealed that Manic controls 169 application identifiers. The list includes banking applications, P2P payment services, BNPL platforms, crypto wallets and exchanges, messaging applications, government services, digital identities, browsers, authenticator apps, and email applications.
See also: SURXRAT: The expansion of an LLM-based Trojan into Android Malware
The focus is on Ukraine, but the targeting extends to Russia, Central and Western Europe, and the United Kingdom. This breadth suggests that the targets are not limited to stealing money, but encompass the entire economic activity, identification, and communications of victims.
From phishing to full control
Manic is distributed via phishing websites and applications that are presented as legitimate utilities. The activity began in February 2026, and in the following months the attackers gradually improved the malware's infrastructure and capabilities.
The newer version incorporates stronger anti-analysis mechanisms and phishing techniques to obtain unlock codes. At the same time, Manic exploits Android's accessibility services and notifications, gaining access to information and interactions that should normally remain protected.
It can record keystrokes, passwords, OTPs and recovery phrases, take screenshots, collect contacts, SMS, call history and notifications, and also track the device's location.
It steals PINs without the need for a fake banking app
One of Manic's most interesting techniques involves PIN interception. The malware places a transparent overlay over an app's real numeric keypad and records the location of each tap.
It then replicates the action on the authentic keyboard, allowing the banking application to function normally. This way, the user may not realize that their password has already been recorded.
See also: Android malware targets Indian users through fake eChallan notifications

Wi-Fi mesh changes data
Manic's most unusual feature is a store-and-forward, through which infected devices can act as intermediate nodes.
If a compromised phone does not have an internet connection, the malware can search for a nearby infected device via Wi-Fi Direct, Bluetooth RFCOMM or BLE GATT. The data is encrypted, cached and transferred to the second device, which then forwards it to the control server.
See also: BeatBanker: Android malware mimics Starlink app to compromise devices
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The system even supports multi-hop routes, allowing data to be transferred across multiple devices. This means that simply disconnecting an infected smartphone from the internet does not guarantee that data theft will stop.
Active development of the threat
Manic’s evolution from May to July 2026 shows that its creators continue to invest in its development. Improved analysis evasion techniques, unlock code theft, and mesh networking point to a threat designed not only for financial fraud, but for long-term surveillance and operational survival.
For Android users, this case is a reminder that installing apps only from trusted sources, restricting accessibility permissions, and paying attention to suspicious phishing messages remain critical defense measures.
