Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The "Manic" Android Malware: A Threat to Global Financial Security and Personal Data




The "Manic" Android malware is a sophisticated piece of code that combines the capabilities of Android banking malware and mobile spyware, allowing it to exfiltrate sensitive data from offline phones via nearby infected devices. This malware poses a significant threat to global financial security and personal data, and its emergence highlights the need for increased vigilance and cooperation between cybersecurity professionals and law enforcement agencies. Stay informed about the latest cybersecurity threats and take immediate action to protect yourself against the "Manic" malware.

  • The "Manic" Android malware can exfiltrate sensitive data from offline phones via nearby infected devices.
  • The malware combines the capabilities of Android banking malware and mobile spyware, posing a significant threat to global financial security and personal data.
  • The malware is distributed via phishing sites and dropper apps, and its development efforts were temporarily abandoned before resurfacing in July 2026.
  • The malware monitors 169 package IDs associated with various financial and messaging services, and facilitates location tracking, notification monitoring, and remote device surveillance.
  • The malware achieves its goals by abusing Android's accessibility services and notification permissions, allowing it to capture lock screen secrets and gather sensitive data.
  • The malware has a store-and-forward relay mechanism, which allows it to exfiltrate data using another device in close proximity to the compromised Android phone.
  • The emergence of the "Manic" malware highlights the need for increased vigilance and cooperation between cybersecurity professionals and law enforcement agencies.
  • Individuals and organizations are advised to take immediate action to protect themselves against the "Manic" malware by staying informed, using reputable security software, and practicing good cybersecurity hygiene.



  • The recent emergence of the "Manic" Android malware has sent shockwaves throughout the cybersecurity community, as it has been discovered that this malicious software is capable of exfiltrating sensitive data from offline phones via nearby infected devices. This malware, which has been actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications, poses a significant threat to global financial security and personal data.

    The "Manic" malware is a sophisticated piece of code that combines the capabilities of Android banking malware and mobile spyware, allowing it to enable financial-fraud capabilities with broader surveillance and device-control features. According to ThreatFabric, a Dutch security company that first observed the malware, "Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud capabilities with broader surveillance and device-control features."

    The malware is distributed via phishing sites and dropper apps impersonating utilities, and its activity dates back to February 2026, when the first domain was registered with a fabricated persona. Active development efforts ensued not long after, with the first wrapper using a booking app lure and the implant appearing by the end of May. However, the malware's development efforts were temporarily abandoned from late June to mid-July, only to resurface around July 13.

    The newer iteration of the wrapper and the implant have been found to incorporate stronger anti-analysis checks and the ability to phishing lock screen secrets. A corresponding panel and API subsequently went live between July 24 and 28. The APK package names linked to the wrapper and implant are tech.intel.dialer.updater (Wrapper), org.honor.secure.helper (Wrapper), org.lenovo.storage.processor (Implant), and dev.huawei.media.helper (Implant).

    An examination of the malware reveals that it monitors 169 package IDs associated with banks, peer-to-peer (P2P) payment and Buy Now, Pay Later (BNPL) services, cryptocurrency wallets and exchanges, messaging apps, government and eID services, browsers, authenticators, and email clients. The majority of the targets are Ukrainian, but also present in the list are apps used in Russia, Central and Western Europe, and the U.K.

    The "Manic" malware is designed to target commercial and military-focused messaging apps, and it facilitates location tracking, notification monitoring, file collection, and remote device surveillance. This allows the operator to keep tabs on a victim's financial activity, communications, and their whereabouts in real-time.

    The malware achieves its goals by abusing Android's accessibility services and notification permissions, effectively allowing it to capture lock screen secrets or serve fake overlays to gather sensitive data or conceal malicious activity by showing black or update screens. Some of the other noteworthy features of the malware include:

    * Intercept keypad interactions and collect passwords, one-time codes, and recovery phrases
    * Leverage accessibility services as a "UI keylogger" to classify and record text along with the app used, and if that app is on the malware's target list
    * Monitor the screen and interact with the device remotely over a WebRTC session
    * Remove the implant from the launcher
    * Record current coordinates and timestamp (and enable device location, if not already)
    * Take screenshots
    * Export contacts, call history, SMS messages, and notifications
    * Obtain a list of installed apps
    * Send SMS to a supplied telephone number along with the provided text
    * Display bogus notifications
    * Delete a selected local file
    * Lock the screen through the accessibility service
    * Attempt to disable Google Play Protect through UI automation

    One of the most unusual aspects of the "Manic" malware is its store-and-forward relay mechanism, which allows it to exfiltrate data using another device that's in close physical proximity to the compromised Android phone if it cannot connect to the attacker-controlled infrastructure. This approach is particularly concerning, as it means that the source device can remain offline while the malware attempts to locate a second infected device that can provide an alternative pathway to the command-and-control (C2) server.

    The "Manic" malware is a significant threat to global financial security and personal data, and its emergence highlights the need for increased vigilance and cooperation between cybersecurity professionals and law enforcement agencies. As ThreatFabric noted, "The evolution observed between May and July 2026, including stronger anti-analysis measures and lock-secret phishing, indicates that Manic remains under active development and continues to expand its capabilities."

    In light of this emerging threat, it is essential for individuals and organizations to take immediate action to protect themselves against the "Manic" malware. This can be achieved by staying informed about the latest cybersecurity threats, using reputable security software, and practicing good cybersecurity hygiene, such as avoiding suspicious links and attachments, and being cautious when using public Wi-Fi networks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Manic-Android-Malware-A-Threat-to-Global-Financial-Security-and-Personal-Data-ehn.shtml

  • https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html


  • Published: Thu Aug 20 12:02:01 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us