New Android malware blurs the line between banking trojan and spyware
Manic has an unusual trick.

Android phone. Mateusz Slodkowski/SOPA Images/LightRocket/Getty.
- Manic targets 169 apps, including banks, crypto wallets, messaging apps, government services and email clients.
- The malware can steal passwords, one-time codes and recovery phrases after gaining device permissions.
- Manic can send stolen data through nearby infected phones using WiFi Direct or Bluetooth.
- Researchers say Android users should avoid sideloading apps from unreliable sources.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Security researchers have identified new Android malware capable of sending stolen data via infected phones back to the scammers.
The newly identified Android malware is dubbed Manic and features some particularly dangerous capabilities.
“Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud capabilities with broader surveillance and device-control features,” ThreatFabric’s Mobile Threat Intelligence (MTI) team says in an analysis.
Manic monitors a total of 169 different apps, including banks, payment services, cryptocurrency wallets and exchanges, messaging apps, government services, authenticator apps, browsers, and email clients.
The Android malware’s primary targets are located in Ukraine. However, Manic also extends its focus to Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.
How does it work? According to ThreatFabric, Manic integrates multiple functions into a comprehensive fraud workflow, progressively giving attackers nearly full control over an infected device.
After obtaining Accessibility and notification access, the malware can:
- Capture the victim’s PIN, password, pattern, fingerprint, or facial recognition to unlock a device.
- Steal sensitive information such as passwords, one-time codes, and recovery phrases.
- Use overlays or fake screens in banking and crypto apps to hide malicious activities and intercept keypad inputs.
- Eavesdrop on a target’s communication by accessing text messages.
- Watch the screen and interact with the device remotely by abusing Accessibility Services privileges.
All without the victims noticing anything.
The collected data and files are encrypted with AES-GCM and placed in a local queue, as the malware is looking for a route to the attacker’s Command and Control (C2) infrastructure.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
A unique feature of the Manic malware is that it can send stolen data to nearby infected devices via WiFi Direct or Bluetooth. This could come in handy if the source device has no internet connection. If no route is available, the data package remains queued, and Manic tries again later.
“As a result, removing direct internet access from an infected device does not necessarily prevent data exfiltration, as another infected phone within radio range may act as its gateway,” researchers explain.
Manic is nowhere to be found in the Google Play Store. Therefore, Android users should exercise caution when sideloading APKs or apps from unreliable sources online.