Security1 distinct publisher3 min readUpdated
ThreatFabric says the Android trojan hands collected data to nearby infected devices over Wi-Fi Direct or Bluetooth until one can reach command and control.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A mesh relay is a routing decision, not a new payload. When a compromised phone has no usable path to command and control, Manic hands what it has collected to a nearby infected device over Wi-Fi Direct or Bluetooth, and the data moves until it reaches a handset that does have egress, according to ThreatFabric [5]. Every control built at the network boundary, the managed VPN, the DNS sinkhole, the blocked C2 domain, sits downstream of that first hop and never sees it.
The condition for it to pay off is physical density of infected devices. That is a real constraint, and it also explains where Manic has been used: ThreatFabric reports it mainly against Ukraine, hitting banks, government services and messaging applications, with observed targeting of Russian and European financial institutions, global crypto and fintech services, and military-focused messaging apps [2]. Populations where handsets sit in the same room, on the same restricted or absent network, are exactly the populations where a device-to-device hop beats waiting for connectivity. Manic already logs keystrokes, throws phishing screens and takes remote control of the phone [3], and adds notification monitoring, location tracking, file harvesting and remote surveillance [4].
Zimperium's ToxicPanda 2.0 numbers point the other way, toward volume. The target list went from 16 financial applications to nearly 350 [10], a roughly 22-fold expansion [14]. That is not better targeting, it is the abandonment of targeting: infect first, find out later which banking app is installed. The 167 supported remote commands [10] and the automated click sequence that turns on Android Wireless Debugging to obtain privilege escalation and shell-level access [12] are the operator-side plumbing for handling that volume without an exploit chain. Note also the geography. A family known mainly for Europe [15] is now aimed at institutions in 16 countries including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia and Panama [11], with samples delivered from Amazon AWS-hosted buckets [13], which makes blocking the delivery host cost the defender more than the attacker.
Grandoreiro is the least novel and the most instructive. Ten years old, Windows, Brazilian in origin, still improving after law enforcement action against it [7]. Acronis found recent samples sideloading through the legitimate Duplicate Files Finder application [8], and says the sandbox checks, VM artifact checks, process blacklisting and environment profiling all run before any attempt to contact C2 [9]. That ordering is the point: a detonation that never produces a callback produces no infrastructure indicator, so the threat feed most organisations actually consume learns nothing from that sample.
Three vendors described these three families in the same week [16] without citing each other. The convergence is in capability rather than code, and the part that should bother whoever owns mobile is narrower than the headline: the phone was already the least governable managed endpoint, and the assumption that you can at least observe or interrupt what leaves it now holds only while it is the sole infected device in the room.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
ThreatFabric detailed Manic, described as Android malware combining banking trojan and spyware capabilities.
Manic is distributed via malicious websites and droppers, and lets attackers log keystrokes, display phishing screens and remotely control the compromised phone for banking and cryptocurrency fraud.
Manic includes spyware capabilities such as notification monitoring, location tracking, file harvesting and remote device surveillance.
ThreatFabric: "A particularly distinctive capability is its offline mesh relay, which allows collected data to move through nearby infected devices over Wi-Fi Direct or Bluetooth when direct C2 access is unavailable."
Manic has mainly been used against Ukraine, including banks, government services and messaging applications, and has also been observed targeting Russian and European financial institutions, global cryptocurrency and fintech services, and military-focused messaging apps.
The Acronis Threat Research Unit warned Grandoreiro remains active, continuing to focus on Latin America, still targeting Europe and North America, with a recent monitored campaign aiming the bulk of attacks at Mexico.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source relay of three vendor reports
Every claim traces to one secondary article summarizing ThreatFabric, Acronis and Zimperium research, with direct quotes but no primary artifacts: no IoCs, hashes, sample counts, victim telemetry or independent corroboration. Technical specificity is high (167 commands, ~350 apps, 16 countries, named sideloaded binary), which supports a middling rather than low score, but the headline mesh-relay behavior rests on a single quoted sentence.
Active campaigns observed, scale unquantified
All three families are described as in active use with named victim geographies and sectors, and Grandoreiro is a decade-old, still-improving operation — real-world deployment is clearly asserted. But no source figure quantifies infections, compromised devices, fraud losses or campaign duration, so the breadth of actual impact cannot be measured.
Headline outruns the quoted evidence
The cluster title and dek promote Manic's phone-to-phone mesh relay as the defining development, yet that behavior is evidenced by one vendor sentence with no detail on range, reliability, prevalence or whether it has been seen exfiltrating data in a real incident. The rest of the article is measured and vendor-attributed, and the ToxicPanda and Grandoreiro figures are concrete, so the overstatement is modest rather than severe.
Vendor threat marketing relayed largely unchallenged
All substantive claims originate with commercial security vendors — ThreatFabric, Acronis Threat Research Unit and Zimperium — that sell fraud, endpoint and mobile threat-defense products and benefit from attention to the threats they detect. The publisher labels each attribution clearly and quotes directly, which is good practice, but adds no independent verification or dissenting voice, and no comment from Google or Amazon whose platforms are named as abused.
Moderate: consistent vendor detail, one publisher
Confidence is limited by single-publisher, single-hop sourcing and the absence of any quantified impact, but raised by internally consistent, precisely attributed technical detail across three independent vendor reports and by the fact that Grandoreiro and ToxicPanda are previously documented families rather than novel unverifiable claims.
security
ToxicPanda 2.0 Widens From 16 Apps to 140, and From Overlays to ADB Shell3 distinct publishers
build
Manic hands stolen PINs to the phone next to it, up to four hops from any egress point1 distinct publisher
security
Defender's own signed driver becomes the bypass: BTR.sys and the week's trusted-component defects1 distinct publisher
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 22, 2026