New Android Trojan Manic Can Steal Passwords and Send Data Through Nearby Smartphones

23.08.2026 2 minutes Author: Newsman

Security researchers have discovered new Android malware capable of sending stolen data to attackers through other infected phones.

The recently discovered Android malware has been named Manic and comes with several particularly dangerous capabilities.

“Manic sits at the intersection of Android banking malware and mobile spyware, combining financial fraud capabilities with broader surveillance and device control features,” according to an analysis by ThreatFabric’s Mobile Threat Intelligence (MTI) team.

Manic monitors a total of 169 different apps, including banking and payment services, cryptocurrency wallets and exchanges, messaging apps, government services, authentication apps, browsers, and email clients.

The Android malware primarily targets users in Ukraine. At the same time, Manic also targets Russian and European financial institutions, global fintech and cryptocurrency services, as well as communication tools focused on the military sector.

How does it work? According to ThreatFabric, Manic combines multiple capabilities into a comprehensive attack workflow, gradually giving attackers near-complete control over the infected device.

After gaining access to Android accessibility features and notifications, the malware can:

  • Capture the victim’s PIN, password, or unlock pattern, as well as data related to unlocking the device using a fingerprint or facial recognition.

  • Steal sensitive information, including passwords, one-time codes, and recovery phrases.

  • Use overlays or fake screens in banking and cryptocurrency apps to conceal malicious activity and intercept data entered through the keyboard.

  • Monitor the victim’s communications by accessing text messages.

  • View the screen and remotely interact with the device by abusing accessibility permissions.

All of this can happen without the victim’s knowledge.

The collected data and files are encrypted using AES-GCM and placed in a local queue while the malware searches for a route to the attackers’ command-and-control (C2) infrastructure.

One of Manic’s unique features is its ability to transmit stolen data through nearby infected devices using Wi-Fi Direct or Bluetooth. This can be useful to attackers if the original infected device does not have internet access. If no route is available, the data packet remains in the queue, and Manic tries again later.

“As a result, removing direct internet access from an infected device does not necessarily prevent data exfiltration, as another infected phone within wireless range can act as its gateway,” the researchers explain.

Manic is not available on Google Play. Android users should therefore be cautious when downloading APK files or apps from untrusted online sources.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.