Manic Android Malware Uses Novel Technique to Exfiltrate Data from Offline Phones
A new Android malware, codenamed Manic, has been discovered targeting financial institutions, government services, and messaging applications, with the ability to exfiltrate data from offline phones via nearby infected devices.

The Manic Android malware has been observed actively targeting various organizations, including Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions. According to ThreatFabric, the malware combines financial-fraud capabilities with broader surveillance and device-control features.
Key Features of Manic Malware
The malware introduces a novel Wi-Fi mesh technique, allowing infected devices to relay data through nearby compromised devices with internet access. It is distributed via phishing sites and dropper apps impersonating utilities. Manic monitors 169 package IDs associated with banks, peer-to-peer payment and Buy Now, Pay Later services, cryptocurrency wallets and exchanges, messaging apps, government and eID services, browsers, authenticators, and email clients.
Targeted Applications and Services
The target set suggests a blend of banking malware and spyware, with financial fraud appearing to be a major objective. The majority of the targets are Ukrainian, but also present in the list are apps used in Russia, Central and Western Europe, and the U.K. Some of the targeted applications and services include:
Data Exfiltration and Relay Mechanism
Manic can capture PIN codes by serving a transparent overlay atop the legitimate numeric keypad in the targeted app. The malware also uses a store-and-forward relay mechanism to exfiltrate data using another device that's in close physical proximity to the compromised Android phone if it cannot connect to the attacker-controlled infrastructure. The relay mechanism works by staging collected files and command results in an encrypted format, finding an infected peer nearby using Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT, and relaying the encrypted package to the peer and forwarding it toward the C2 server.
Persistence and Evolution
Persistence relies on background workers, alarms, and the Accessibility and notification services, which maintain C2 communication, process commands, upload queued data, and synchronize the offline mesh. The evolution observed between May and July 2026, including stronger anti-analysis measures and lock-secret phishing, indicates that Manic remains under active development and continues to expand its capabilities. ThreatFabric notes that the malware's ability to weaponize another compromised Android device as a gateway means that disconnecting an infected device from the internet does not necessarily prevent data exfiltration.





