Security3 distinct publishers3 min readUpdated
ThreatFabric says the Android spyware encrypts stolen data and relays it over Wi-Fi Direct and Bluetooth when it cannot reach its C2, using up to four hops by default.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
ThreatFabric says the Android spyware encrypts stolen data and relays it over Wi-Fi Direct and Bluetooth when it cannot reach its C2, using up to four hops by default.
ThreatFabric has documented an Android malware family called Manic that, when a compromised device cannot reach its command-and-control server, encrypts what it has collected and moves it out through other infected devices over Wi-Fi Direct or Bluetooth [1][8][9]. According to the company, that works even on a device with no internet connectivity of its own, as long as another infected device is within Wi-Fi or Bluetooth range [12].
That is the part worth sitting with. Cutting a handset off the network, sinkholing a C2 domain, or parking a suspect device in a segment with no egress all assume the malware has exactly one route out. Manic treats the network path as the preferred route and radio proximity as the backup.
The collection side is more familiar. ThreatFabric says Manic has been active since at least February and combines spyware, banking fraud, and remote control capabilities [2]. It targets at least 169 banking, government and eID, payment, crypto wallet, messaging, and authenticator or 2FA apps, with users in Ukraine the primary focus [3]. The malware places transparent overlays on the numeric keypads of legitimate apps, captures the victim's taps, and reproduces them through Android Accessibility so the real app keeps working normally [4]. Once it holds Accessibility and notification access, it can capture the lock PIN or password, intercept notifications and SMS, collect files and location data, monitor the screen, and hand operators remote control over WebRTC sessions [5].
The stolen text is not dumped raw. "Manic uses its Accessibility service as a UI keylogger," ThreatFabric says, and the malware "classifies captured text before recording it, distinguishing lock-screen input, recovery-phrase candidates, four- to six-digit SMS codes, passwords, long messages, email logins, and ordinary text" [7]. Captured information is categorised by type, which the researchers say makes it more readily exploitable by the operators [6]. Credentials arriving pre-sorted are credentials that get used faster.
On transport, ThreatFabric describes an ordered fallback: "Manic first attempts to use an established Wi-Fi Direct peer, then queries Bluetooth and BLE peers to determine whether they have internet connectivity" [10]. If needed it can use multi-hop routes, with newly queued items configured for a maximum of four relay hops by default [11]. In practice that means stolen data can transit as many as four intermediary infected handsets before reaching one that uploads it [17].
Targeting spans applications used across Central and Western Europe, including the UK, as well as Russia, with the primary focus on banking and government or eID applications in Ukraine plus global fintech and cryptocurrency services [13]. The infection vector remains unknown, though researchers observed a wrapper delivering the main payload in late May, followed by expansion of the existing infrastructure [14]. In July an updated wrapper with stronger anti-analysis checks and in-memory DEX loading appeared, alongside a new panel and API [15].
Watch whether the four-hop default moves, since it is a configuration value rather than a limit, and whether peer relaying shows up in other Android families now that it has been published. The standing advice is unchanged and still the only reliable control here: no APKs from obscure sources or unofficial portals, deny Accessibility permissions unless a trusted application genuinely needs them, and run Play Protect scans [16]. For responders, the practical adjustment is that a quarantined phone with Bluetooth and Wi-Fi radios still on is not quarantined.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
A new Android malware named Manic targeting users in multiple European countries has a fallback mechanism for exfiltrating data through nearby infected devices, according to ThreatFabric analysis.
Manic has been active since at least February and combines spyware, banking fraud, and remote control capabilities.
Manic targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA apps, with users in Ukraine being the primary focus.
ThreatFabric found Manic uses transparent overlays on the numeric keypads of legitimate applications to capture victims' taps and reproduce them through Android Accessibility, allowing the legitimate applications to continue functioning normally.
After obtaining Accessibility and notification access permissions, Manic can capture the lock PIN/password, intercept notifications and SMS messages, collect files and location data, monitor the screen, and provide remote control to operators via WebRTC sessions.
The captured information is categorized by type, making the data more readily exploitable for the malware operators.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-vendor technical analysis, no independent verification
The technical substance is specific and internally consistent across all three publishers - 169 monitored packages, overlay-plus-Accessibility PIN capture, classifying UI keylogger, WebRTC takeover, AES-GCM queue with Wi-Fi Direct/Bluetooth/BLE peer relay and a four-hop default - and The Hacker News adds named wrapper and implant package IDs. But every article derives from one ThreatFabric report shared with the press; there is no second research team, no platform-vendor confirmation, and one supplied item is a duplicate URL of another. Delivery is also inconsistently reported (vector 'unknown' versus phishing sites and utility droppers), and the derived hop-chain arithmetic is unresolvable from the text.
Live campaign with maturing infrastructure, prevalence unmeasured
There is real-world footprint evidence: infrastructure registered in February 2026, an implant by end of May, a second deployment around July 13, a panel and API live July 24-28, two wrapper and two implant package IDs, and 169 targeted packages weighted toward Ukraine. What is absent is any measure of scale - no infected-device counts, no telemetry, no confirmed fraud losses, and specifically no observation of the proximity mesh actually relaying data in the field, which requires a local density of infected handsets that no source quantifies. ThreatFabric also assesses the family as still under development.
Real capability, headline outruns demonstrated field use
The mesh relay is a documented code capability with a stated four-hop default, and the reporting is measured in wording. The gap comes from framing: headlines and deks foreground exfiltration 'through the phone next to yours' and 'from offline phones', which presumes a neighbourhood of infected devices that no source evidences, while the same reports concede the family is still under development, the vector is disputed, and no infection volumes exist. The derived four-intermediary-handsets reading pushes further than the text supports.
Vendor-originated threat intel with commercial surround
The sole primary source is a commercial mobile-security vendor that shared its technical report with the press and whose product line addresses exactly this threat class; naming and branding a new family is reputationally and commercially useful. The BleepingComputer item also appends a sponsored 'Blue Report 2026' promotion to the news copy. Nothing suggests the technical findings are shaped by these incentives, and the publishers are conventional security trade press, so the pressure is structural rather than evident distortion.
Technique facts solid, scale and delivery uncertain
High confidence that Manic exists and that the described capabilities are present in the analyzed samples: three independent publishers reproduce the same specifics, including quoted report passages and named package IDs, within hours of each other. Confidence is held down by single-vendor origin, one duplicated source, an explicit conflict on the infection vector, complete absence of prevalence or victim data, and no field observation of the headline mesh-relay behaviour.
security
ToxicPanda 2.0 Widens From 16 Apps to 140, and From Overlays to ADB Shell2 distinct publishers
build
Sideloading becomes a registered activity: budgeting for Android's September 2026 deadline1 distinct publisher
security
Android's "unverified developer" flow ships, and the burden shifts to whoever builds the APK1 distinct publisher
build
Geofencing beats GPS polling on power, then loses to the OEM battery optimiser1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026
1 article · August 20, 2026
2 articles · August 20, 2026