New Android Malware Steals Banking PINs and Relays Data Through Infected Phones
Key Takeaways A new Android malware, dubbed “Manic,” integrates banking fraud capabilities with full-fledged spyware functionalities. Manic can stealthily capture banking PINs, monitor...
Key Takeaways
- A new Android malware, dubbed “Manic,” integrates banking fraud capabilities with full-fledged spyware functionalities.
- Manic can stealthily capture banking PINs, monitor screens in real-time, hijack banking sessions, and exfiltrate sensitive data including files, messages, and location.
- Uniquely, Manic forms a peer-to-peer mesh network among infected devices to relay stolen data, even if the primary device lacks an internet connection.
- The malware targets 169 applications across banking, government ID, payment, cryptocurrency, authenticator, and messaging platforms, with a focus on Ukraine, Russia, and several European countries.
- Users are urged to avoid unofficial APKs, be cautious with Accessibility permission requests, and maintain active Google Play Protect.
Sophisticated Android Malware “Manic” Combines Banking Theft with Covert Spyware
A recently uncovered Android malware family, named Manic, represents a significant evolution in mobile threats, seamlessly blending banking fraud with comprehensive spyware capabilities. What truly distinguishes Manic, however, is its innovative data exfiltration mechanism: it can leverage nearby compromised devices to relay stolen information, effectively creating a self-healing mesh network even when the initial infected phone lacks an internet connection.
Table Of Content
Unpacking Manic’s Multifaceted Threat
The discovery was made by the Mobile Threat Intelligence team at ThreatFabric, who characterized Manic as a hybrid threat operating at the nexus of Android banking trojans and advanced mobile spyware. Far from specializing in a single form of deception, Manic furnishes its operators with an extensive arsenal for illicit activities. This includes the ability to record a victim’s PIN, observe their screen in real-time, seize control of banking sessions, and extract files, messages, and precise location data from the compromised device.
ThreatFabric’s analysis tracks Manic’s foundational infrastructure back to February 2026, with development intensifying through the spring. A more sophisticated iteration emerged by July, incorporating enhanced anti-analysis defenses and the ability to load code directly into memory, making it harder to detect and dismantle.
Broad Target Scope and Stealthy PIN Capture
Manic currently monitors a staggering 169 applications. This extensive list encompasses critical services such as banks, government identity portals, payment processors, cryptocurrency wallets and exchanges, authenticator applications, and popular messaging platforms. While Ukraine appears to be a primary focus, with national banks and eID services heavily targeted, the malware’s reach extends to Russia, Poland, Germany, the Czech Republic, Slovakia, and the UK, alongside various global fintech and crypto platforms.
This diverse targeting reveals a dual motivation for Manic’s operators. The inclusion of financial institutions and crypto wallets clearly signals an intent for direct financial theft. However, the monitoring of government identity applications and both commercial and military-oriented messaging services suggests a deeper objective: gaining insight into victims’ communications and digital identities, not merely their bank balances.
Unlike most banking trojans that rely on overlay attacks—presenting a fake login screen over legitimate apps—Manic employs a more insidious method for credential theft. Once it secures Accessibility and notification permissions, it places a transparent overlay specifically over the numeric keypad of a genuine banking application. This allows it to silently record each tap made by the victim. These recorded taps are then replayed through Android’s Accessibility service to the actual application, allowing the transaction to proceed normally while the PIN is secretly logged in the background.
A similar tactic is applied to the device’s lock screen, where Manic attempts to capture and later reuse the unlock code or pattern. Coupled with SMS and notification interception, and live WebRTC screen-sharing sessions that enable attackers to view and interact with the phone remotely, Manic effectively grants adversaries full, hands-on control over a victim’s device.
The Peer-to-Peer Exfiltration Network
The most innovative aspect of Manic’s design lies in its data exfiltration strategy. Should an infected phone fail to establish a direct connection to its command-and-control server, the malware does not cease its efforts. Instead, it encrypts the collected data, stores it locally, and then actively scans for other infected phones nearby using Wi-Fi Direct, Bluetooth, or Bluetooth Low Energy (BLE). If another compromised device with internet access is found, the initial phone transmits the encrypted package to it. This second device then forwards the data to the command-and-control server, effectively transforming ordinary infected phones into an unwitting mesh network for data exfiltration.
This peer-relay approach significantly complicates defensive measures. Simply isolating a single infected phone by cutting its internet connection is insufficient to prevent data leakage, provided another compromised device is within wireless range. This blend of covert PIN capture, profound device takeover capabilities, and a resilient, self-healing exfiltration network makes Manic considerably more challenging to detect and contain than conventional banking trojans.
ThreatFabric’s continued tracking of this campaign, alongside other recent 2026 discoveries such as the WindRelay NFC relay malware and the human-mimicking Herodotus trojan, highlights a growing trend in Android threats: the integration of multiple sophisticated fraud techniques into a single, comprehensive platform.
What You Should Do
- Avoid Sideloading APKs: Only download applications from trusted sources like the Google Play Store. Sideloading APKs from unofficial websites significantly increases the risk of malware infection.
- Scrutinize Permissions: Be extremely cautious when any app, especially those unrelated to accessibility features, requests Accessibility permissions. This permission is heavily abused by malware like Manic for stealthy data capture and device control.
- Keep Google Play Protect Active: Ensure Google Play Protect is enabled on your Android device. It provides a crucial layer of defense against known malware families.
- Regularly Update Your OS and Apps: Keep your Android operating system and all applications updated to benefit from the latest security patches.
- Use Strong, Unique Passwords and MFA: Implement strong, unique passwords for all your online accounts and enable multi-factor authentication (MFA) wherever possible, especially for banking and critical services.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.