Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake CAPTCHA Installs Malware That Kills 145 Security Processes
August 20, 2026
New Android Malware Steals Banking PINs and Relays Data Through Infected Phones
August 20, 2026
Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Mailboxes
August 20, 2026
Home/CyberSecurity News/New Android Malware Steals Banking PINs and Relays Data Through Infected Phones
CyberSecurity News

New Android Malware Steals Banking PINs and Relays Data Through Infected Phones

Key Takeaways A new Android malware, dubbed “Manic,” integrates banking fraud capabilities with full-fledged spyware functionalities. Manic can stealthily capture banking PINs, monitor...

Sarah simpson
Sarah simpson
August 20, 2026 4 Min Read
2 0

Key Takeaways

  • A new Android malware, dubbed “Manic,” integrates banking fraud capabilities with full-fledged spyware functionalities.
  • Manic can stealthily capture banking PINs, monitor screens in real-time, hijack banking sessions, and exfiltrate sensitive data including files, messages, and location.
  • Uniquely, Manic forms a peer-to-peer mesh network among infected devices to relay stolen data, even if the primary device lacks an internet connection.
  • The malware targets 169 applications across banking, government ID, payment, cryptocurrency, authenticator, and messaging platforms, with a focus on Ukraine, Russia, and several European countries.
  • Users are urged to avoid unofficial APKs, be cautious with Accessibility permission requests, and maintain active Google Play Protect.

Sophisticated Android Malware “Manic” Combines Banking Theft with Covert Spyware

A recently uncovered Android malware family, named Manic, represents a significant evolution in mobile threats, seamlessly blending banking fraud with comprehensive spyware capabilities. What truly distinguishes Manic, however, is its innovative data exfiltration mechanism: it can leverage nearby compromised devices to relay stolen information, effectively creating a self-healing mesh network even when the initial infected phone lacks an internet connection.

Table Of Content

  • Key Takeaways
  • Sophisticated Android Malware “Manic” Combines Banking Theft with Covert Spyware
  • Unpacking Manic’s Multifaceted Threat
  • Broad Target Scope and Stealthy PIN Capture
  • The Peer-to-Peer Exfiltration Network
  • What You Should Do

Unpacking Manic’s Multifaceted Threat

The discovery was made by the Mobile Threat Intelligence team at ThreatFabric, who characterized Manic as a hybrid threat operating at the nexus of Android banking trojans and advanced mobile spyware. Far from specializing in a single form of deception, Manic furnishes its operators with an extensive arsenal for illicit activities. This includes the ability to record a victim’s PIN, observe their screen in real-time, seize control of banking sessions, and extract files, messages, and precise location data from the compromised device.

ThreatFabric’s analysis tracks Manic’s foundational infrastructure back to February 2026, with development intensifying through the spring. A more sophisticated iteration emerged by July, incorporating enhanced anti-analysis defenses and the ability to load code directly into memory, making it harder to detect and dismantle.

Broad Target Scope and Stealthy PIN Capture

Manic currently monitors a staggering 169 applications. This extensive list encompasses critical services such as banks, government identity portals, payment processors, cryptocurrency wallets and exchanges, authenticator applications, and popular messaging platforms. While Ukraine appears to be a primary focus, with national banks and eID services heavily targeted, the malware’s reach extends to Russia, Poland, Germany, the Czech Republic, Slovakia, and the UK, alongside various global fintech and crypto platforms.

This diverse targeting reveals a dual motivation for Manic’s operators. The inclusion of financial institutions and crypto wallets clearly signals an intent for direct financial theft. However, the monitoring of government identity applications and both commercial and military-oriented messaging services suggests a deeper objective: gaining insight into victims’ communications and digital identities, not merely their bank balances.

Unlike most banking trojans that rely on overlay attacks—presenting a fake login screen over legitimate apps—Manic employs a more insidious method for credential theft. Once it secures Accessibility and notification permissions, it places a transparent overlay specifically over the numeric keypad of a genuine banking application. This allows it to silently record each tap made by the victim. These recorded taps are then replayed through Android’s Accessibility service to the actual application, allowing the transaction to proceed normally while the PIN is secretly logged in the background.

A similar tactic is applied to the device’s lock screen, where Manic attempts to capture and later reuse the unlock code or pattern. Coupled with SMS and notification interception, and live WebRTC screen-sharing sessions that enable attackers to view and interact with the phone remotely, Manic effectively grants adversaries full, hands-on control over a victim’s device.

The Peer-to-Peer Exfiltration Network

The most innovative aspect of Manic’s design lies in its data exfiltration strategy. Should an infected phone fail to establish a direct connection to its command-and-control server, the malware does not cease its efforts. Instead, it encrypts the collected data, stores it locally, and then actively scans for other infected phones nearby using Wi-Fi Direct, Bluetooth, or Bluetooth Low Energy (BLE). If another compromised device with internet access is found, the initial phone transmits the encrypted package to it. This second device then forwards the data to the command-and-control server, effectively transforming ordinary infected phones into an unwitting mesh network for data exfiltration.

This peer-relay approach significantly complicates defensive measures. Simply isolating a single infected phone by cutting its internet connection is insufficient to prevent data leakage, provided another compromised device is within wireless range. This blend of covert PIN capture, profound device takeover capabilities, and a resilient, self-healing exfiltration network makes Manic considerably more challenging to detect and contain than conventional banking trojans.

ThreatFabric’s continued tracking of this campaign, alongside other recent 2026 discoveries such as the WindRelay NFC relay malware and the human-mimicking Herodotus trojan, highlights a growing trend in Android threats: the integration of multiple sophisticated fraud techniques into a single, comprehensive platform.

What You Should Do

  • Avoid Sideloading APKs: Only download applications from trusted sources like the Google Play Store. Sideloading APKs from unofficial websites significantly increases the risk of malware infection.
  • Scrutinize Permissions: Be extremely cautious when any app, especially those unrelated to accessibility features, requests Accessibility permissions. This permission is heavily abused by malware like Manic for stealthy data capture and device control.
  • Keep Google Play Protect Active: Ensure Google Play Protect is enabled on your Android device. It provides a crucial layer of defense against known malware families.
  • Regularly Update Your OS and Apps: Keep your Android operating system and all applications updated to benefit from the latest security patches.
  • Use Strong, Unique Passwords and MFA: Implement strong, unique passwords for all your online accounts and enable multi-factor authentication (MFA) wherever possible, especially for banking and critical services.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Mailboxes

Next Post

Fake CAPTCHA Installs Malware That Kills 145 Security Processes

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Red Hat OpenShift CVE-2023-39418 Exposes Internal Services
August 20, 2026
OpenAI Pauses AI Model Training Over 0-Day Discovery Concerns
August 20, 2026
Cisco AnyConnect VPN Client Critical RCE Vulnerability CVE-2020-3556 Patched
August 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us