AUTO-UPDATED

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

The newly discovered Manic Android malware is actively targeting financial, government, and military applications across Ukraine, Europe, and Russia using advanced surveillance and novel data-relay techniques.

Key Points

  • Manic functions as a hybrid of banking malware and spyware, monitoring 169 specific package IDs for financial fraud and device surveillance.
  • The malware utilizes a unique Wi-Fi mesh relay system, allowing infected devices to exfiltrate data through nearby compromised phones even when offline.
  • Attackers distribute the malware via phishing sites and dropper apps that impersonate legitimate utilities like dialers and storage processors.
  • Key features include a UI keylogger, remote screen interaction via WebRTC, and the ability to capture PIN codes using transparent overlays.
  • Active development since February 2026 has resulted in stronger anti-analysis protections and improved methods for phishing lock screen credentials.

Why it Matters

This malware represents a significant escalation in mobile threats by combining traditional financial theft with sophisticated, multi-hop data exfiltration capabilities. Its ability to bypass internet restrictions by leveraging nearby infected devices poses a severe risk to users in sensitive sectors, including government and military personnel.
Internet Published by info@thehackernews.com (The Hacker News)
Read original