Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Exfiltration of Sensitive Data: The Rise of Manic, a Sophisticated Android Malware




The exfiltration of sensitive data by a sophisticated Android malware, dubbed Manic, has made headlines in the cybersecurity world. Developed by a group of skilled hackers, Manic combines the functionalities of banking fraud and spyware, making it a formidable threat to mobile device users. In this article, we delve into the capabilities of Manic and explore the measures that can be taken to protect devices from this evolving threat.

  • Manic is a sophisticated Android malware that combines banking fraud and spyware capabilities.
  • It has been active in the wild since at least February 2026 and was developed in late March and April 2026.
  • Manic primarily targets Ukrainian banks, government, and identity services, as well as Russian and European financial institutions.
  • The malware can exfiltrate data even when the infected device is offline using a store-and-forward relay mechanism.
  • It searches for nearby infected devices over Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT.
  • Manic offers remote control of the device through WebRTC, allowing attackers to view the screen and interact with it.
  • Defenders should monitor for unusual Accessibility service grants and unexpected Bluetooth or Wi-Fi Direct connections.
  • The malware is an evolving Android fraud platform designed for Device Takeover, combining credential and authentication theft with live screen monitoring and remote control.
  • Mobile device users should take necessary precautions to protect their devices, including monitoring for unusual activity and keeping software up to date.



  • Manic, a recently discovered Android malware, has been making headlines in the cybersecurity world due to its sophisticated capabilities and exfiltration techniques. Developed by a group of skilled hackers, Manic combines the functionalities of banking fraud and spyware, making it a formidable threat to mobile device users.

    According to a report published by ThreatFabric's Mobile Threat Intelligence team, Manic has been active in the wild since at least February 2026, with its development and production phases taking place in late March and April of the same year. The malware's targeting is strongly focused on Ukraine, covering Ukrainian banks, government, and identity services, as well as Russian and European financial institutions, global fintech, and cryptocurrency services, and military-focused communications.

    Manic's unique selling point is its ability to exfiltrate data even when the infected device is offline. This is made possible by its store-and-forward relay mechanism, which allows the malware to collect files and command results and encrypt them with AES-GCM. The collected data is then placed in a local queue, allowing the source device to remain offline while the malware searches for another infected device that can provide a route to the C2 infrastructure.

    The malware's search for nearby infected devices takes place over Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT, and supports chains of up to four relay hops. This allows the malware to bypass traditional internet connectivity and exfiltrate data even when the device is offline.

    In addition to its exfiltration capabilities, Manic also offers remote control of the device through WebRTC, allowing the attackers to view the screen and interact with it using Android's Accessibility features. The malware can also hide its activity with black screens, fake screens, or fake update messages, while also covering permission requests.

    The July version of the malware went a step further by removing itself from the device's app launcher, keeping it out of the normal app list and allowing attackers to activate it through its wrapper or a deep link.

    The combination of Manic's capabilities is complete in an uncomfortable way, offering credential theft, live screen monitoring, authentication interception, device takeover, and exfiltration paths that don't require the infected device to have internet access at all. Defenders are advised to monitor for unusual Accessibility service grants and unexpected Bluetooth or Wi-Fi Direct connections from phones that aren't actively transferring files.

    The ThreatFabric report concludes that Manic is an evolving Android fraud platform designed for Device Takeover, combining credential and authentication theft with live screen monitoring and remote control. Its targeting spans banks, payment and cryptocurrency services, eID applications, and messengers, with a strong focus on Ukraine.

    In light of this discovery, it is essential for mobile device users to be aware of the potential risks associated with Manic and take necessary precautions to protect their devices. This includes monitoring for unusual activity, keeping software up to date, and using reputable antivirus software.

    The rise of Manic highlights the evolving nature of mobile malware and the need for continued vigilance in the face of emerging threats. As cybersecurity experts, it is crucial that we stay informed and adapt our strategies to counter these threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Exfiltration-of-Sensitive-Data-The-Rise-of-Manic-a-Sophisticated-Android-Malware-ehn.shtml

  • https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html


  • Published: Thu Aug 20 15:29:04 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us