HomeSecurityManic Android malware: Banking trojan and spyware

Manic Android malware: Banking trojans and spyware

A new and highly sophisticated threat for Android has emerged, dubbed Manic, targeting a wide range of financial, government, and communications applications. According to cybersecurity firm ThreatFabric, the malware is primarily focused on Ukrainian organizations, while also targeting Russian and European banks, fintech services, cryptocurrency platforms, and communications applications military.

Article Image: Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

Its capabilities far exceed those of typical banking malware. Manic combines financial fraud functionality with spyware features, allowing its operator to monitor the device, collect data, and perform remote actions.

169 applications in the spotlight

ThreatFabric's analysis revealed that Manic controls 169 application identifiers. The list includes banking applications, P2P payment services, BNPL platforms, crypto wallets and exchanges, messaging applications, government services, digital identities, browsers, authenticator apps, and email applications.

See also: SURXRAT: The expansion of an LLM-based Trojan into Android Malware

The focus is on Ukraine, but the targeting extends to Russia, Central and Western Europe, and the United Kingdom. This breadth suggests that the targets are not limited to stealing money, but encompass the entire economic activity, identification, and communications of victims.

From phishing to full control

Manic is distributed via phishing websites and applications that are presented as legitimate utilities. The activity began in February 2026, and in the following months the attackers gradually improved the malware's infrastructure and capabilities.

The newer version incorporates stronger anti-analysis mechanisms and phishing techniques to obtain unlock codes. At the same time, Manic exploits Android's accessibility services and notifications, gaining access to information and interactions that should normally remain protected.

It can record keystrokes, passwords, OTPs and recovery phrases, take screenshots, collect contacts, SMS, call history and notifications, and also track the device's location.

It steals PINs without the need for a fake banking app

One of Manic's most interesting techniques involves PIN interception. The malware places a transparent overlay over an app's real numeric keypad and records the location of each tap.

It then replicates the action on the authentic keyboard, allowing the banking application to function normally. This way, the user may not realize that their password has already been recorded.

See also: Android malware targets Indian users through fake eChallan notifications

Article Image: Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Wi-Fi mesh changes data

Manic's most unusual feature is a store-and-forward, through which infected devices can act as intermediate nodes.

If a compromised phone does not have an internet connection, the malware can search for a nearby infected device via Wi-Fi Direct, Bluetooth RFCOMM or BLE GATT. The data is encrypted, cached and transferred to the second device, which then forwards it to the control server.

See also: BeatBanker: Android malware mimics Starlink app to compromise devices

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The system even supports multi-hop routes, allowing data to be transferred across multiple devices. This means that simply disconnecting an infected smartphone from the internet does not guarantee that data theft will stop.

Active development of the threat

Manic’s evolution from May to July 2026 shows that its creators continue to invest in its development. Improved analysis evasion techniques, unlock code theft, and mesh networking point to a threat designed not only for financial fraud, but for long-term surveillance and operational survival.

For Android users, this case is a reminder that installing apps only from trusted sources, restricting accessibility permissions, and paying attention to suspicious phishing messages remain critical defense measures.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS