The newly discovered Manic Android malware is actively targeting financial, government, and military applications across Ukraine, Europe, and Russia using advanced surveillance and novel data-relay techniques.
Key Points
- Manic functions as a hybrid of banking malware and spyware, monitoring 169 specific package IDs for financial fraud and device surveillance.
- The malware utilizes a unique Wi-Fi mesh relay system, allowing infected devices to exfiltrate data through nearby compromised phones even when offline.
- Attackers distribute the malware via phishing sites and dropper apps that impersonate legitimate utilities like dialers and storage processors.
- Key features include a UI keylogger, remote screen interaction via WebRTC, and the ability to capture PIN codes using transparent overlays.
- Active development since February 2026 has resulted in stronger anti-analysis protections and improved methods for phishing lock screen credentials.