Skip to main content
LiMP VPN
All news

Manic Android Malware Steals Bank Data Even from Offline Phones

Manic Android Malware Steals Bank Data Even from Offline Phones

In short: Security researchers at ThreatFabric published a detailed analysis of a new Android malware family called Manic on August 20, 2026. It targets 169 banking, payment, crypto, messaging, and 2FA apps — including Russian financial services — and can exfiltrate stolen data through nearby infected devices via Bluetooth and Wi-Fi Direct, even when the victim's phone has no internet connection.

What Manic Can Do

Manic blends banking trojan and spyware capabilities. After installation, it requests Android Accessibility Service permissions to:

  • Intercept lock-screen PIN and password input;
  • Overlay fake login screens on top of real banking apps to capture credentials;
  • Copy incoming SMS one-time codes (OTPs);
  • Read cryptocurrency wallet recovery phrases;
  • Capture notifications, files, and location data;
  • Allow operators to monitor and remotely control the device screen.

The 169 targeted app packages span banks, government/eID services, crypto wallets, messaging apps, and two-factor authenticators. ThreatFabric identifies Ukraine as the primary target, alongside Russia, Poland, Czech Republic, the UK, and other European countries.

Offline Relay: The Novel Technique

Manic's most distinctive feature is its store-and-forward relay mechanism: if the infected phone loses internet connectivity, the malware finds nearby infected devices via Wi-Fi Direct or Bluetooth/BLE and routes encrypted stolen data through them. The default relay chain allows up to four hops.

This effectively creates a decentralised mesh network of compromised phones — each can temporarily act as a bridge to relay stolen data to the C2 server. The data reaches the attackers even if the victim is in a subway, on an airplane, or in an area with poor connectivity.

The relay selection algorithm: Manic first checks for an active Wi-Fi Direct connection, then queries Bluetooth and BLE peers for internet access, and routes the payload through the first available node. This makes blocking such traffic significantly harder for conventional security tools.

How Manic Spreads

Manic has not been found on Google Play — Google confirmed this and noted that Play Protect automatically protects users from known samples. Infections come from phishing sites and dropper apps disguised as utilities: "system updates," security tools, or helpful productivity apps.

Manic's infrastructure first appeared in February 2026. Active distribution was observed by May. An updated version with stronger anti-analysis capabilities appeared in July, suggesting the group continues to actively develop the tool.

How to Protect Your Phone

The core rule: only install apps from the official Google Play store. Any offer to download an "update" or app via a link in a messenger, ad banner, or browser should be treated as a red flag.

Check Android's Accessibility settings (Settings → Accessibility → Installed Services): no app should be listed there that you did not intentionally activate. This is the specific permission Manic abuses to intercept password input.

At the network privacy level, LiMP VPN encrypts all device traffic and hides visited domains from network-level surveillance. This is particularly relevant in public Wi-Fi and Bluetooth environments — exactly the settings where Manic hunts for relay bridges. The app is available for iOS and Android.

Sources

Manic Android Malware Steals Bank Data Even from Offline Phones