Published · 3d agoSecurity3 min read
Manic's fallback channel: Android malware that exfiltrates through the phone next to yours
ThreatFabric says the Android spyware encrypts stolen data and relays it over Wi-Fi Direct and Bluetooth when it cannot reach its C2, using up to four hops by default.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- A new Android malware named Manic targeting users in multiple European countries has a fallback mechanism for exfiltrating data through nearby infected devices, according to ThreatFabric analysis.
- Manic has been active since at least February and combines spyware, banking fraud, and remote control capabilities.
- Manic targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA apps, with users in Ukraine being the primary focus.
- ThreatFabric found Manic uses transparent overlays on the numeric keypads of legitimate applications to capture victims' taps and reproduce them through Android Accessibility, allowing the legitimate applications to continue functioning normally.
- After obtaining Accessibility and notification access permissions, Manic can capture the lock PIN/password, intercept notifications and SMS messages, collect files and location data, monitor the screen, and provide remote control to operators via WebRTC sessions.
Compiled by The WatchSomething wrong?How this is made
Why it matters
ThreatFabric has documented an Android malware family called Manic that, when a compromised device cannot reach its command-and-control server, encrypts what it has collected and moves it out through other infected devices over Wi-Fi Direct or Bluetooth [1][8][9]. According to the company, that works even on a device with no internet connectivity of its own, as long as another infected device is within Wi-Fi or Bluetooth range [12].
That is the part worth sitting with. Cutting a handset off the network, sinkholing a C2 domain, or parking a suspect device in a segment with no egress all assume the malware has exactly one route out. Manic treats the network path as the preferred route and radio proximity as the backup.
The collection side is more familiar. ThreatFabric says Manic has been active since at least February and combines spyware, banking fraud, and remote control capabilities [2]. It targets at least 169 banking, government and eID, payment, crypto wallet, messaging, and authenticator or 2FA apps, with users in Ukraine the primary focus [3]. The malware places transparent overlays on the numeric keypads of legitimate apps, captures the victim's taps, and reproduces them through Android Accessibility so the real app keeps working normally [4]. Once it holds Accessibility and notification access, it can capture the lock PIN or password, intercept notifications and SMS, collect files and location data, monitor the screen, and hand operators remote control over WebRTC sessions [5].
The stolen text is not dumped raw. "Manic uses its Accessibility service as a UI keylogger," ThreatFabric says, and the malware "classifies captured text before recording it, distinguishing lock-screen input, recovery-phrase candidates, four- to six-digit SMS codes, passwords, long messages, email logins, and ordinary text" [7]. Captured information is categorised by type, which the researchers say makes it more readily exploitable by the operators [6]. Credentials arriving pre-sorted are credentials that get used faster.
On transport, ThreatFabric describes an ordered fallback: "Manic first attempts to use an established Wi-Fi Direct peer, then queries Bluetooth and BLE peers to determine whether they have internet connectivity" [10]. If needed it can use multi-hop routes, with newly queued items configured for a maximum of four relay hops by default [11]. In practice that means stolen data can transit as many as four intermediary infected handsets before reaching one that uploads it [17].
Targeting spans applications used across Central and Western Europe, including the UK, as well as Russia, with the primary focus on banking and government or eID applications in Ukraine plus global fintech and cryptocurrency services [13]. The infection vector remains unknown, though researchers observed a wrapper delivering the main payload in late May, followed by expansion of the existing infrastructure [14]. In July an updated wrapper with stronger anti-analysis checks and in-memory DEX loading appeared, alongside a new panel and API [15].
Watch whether the four-hop default moves, since it is a configuration value rather than a limit, and whether peer relaying shows up in other Android families now that it has been published. The standing advice is unchanged and still the only reliable control here: no APKs from obscure sources or unofficial portals, deny Accessibility permissions unless a trusted application genuinely needs them, and run Play Protect scans [16]. For responders, the practical adjustment is that a quarantined phone with Bluetooth and Wi-Fi radios still on is not quarantined.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A new Android malware named Manic targeting users in multiple European countries has a fallback mechanism for exfiltrating data through nearby infected devices, according to ThreatFabric analysis.
- [2]
Manic has been active since at least February and combines spyware, banking fraud, and remote control capabilities.
ReportedView cited source - [3]
Manic targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA apps, with users in Ukraine being the primary focus.
ReportedView cited source - [4]
ThreatFabric found Manic uses transparent overlays on the numeric keypads of legitimate applications to capture victims' taps and reproduce them through Android Accessibility, allowing the legitimate applications to continue functioning normally.
ReportedView cited source - [5]
After obtaining Accessibility and notification access permissions, Manic can capture the lock PIN/password, intercept notifications and SMS messages, collect files and location data, monitor the screen, and provide remote control to operators via WebRTC sessions.
ReportedView cited source - [6]
The captured information is categorized by type, making the data more readily exploitable for the malware operators.
ReportedView cited source
Sources & coverage · 4 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comBill Toulas3d agoNew Manic Android malware can exfiltrate data through nearby devices
- thehackernews.com



