Disconnecting a compromised phone from the internet is usually the first line of defense, but a nasty new piece of Android malware just found a way to bridge the air gap.
ThreatFabric’s Mobile Threat Intelligence team identified Manic as a malware family that combines banking fraud with spyware and remote-control capabilities. The campaign is primarily focused on Ukraine, but its reach extends to financial institutions in Russia and Europe, global fintech and cryptocurrency services, and military-focused messaging applications.
The malware monitors 169 Android package IDs covering banks, payment services, crypto wallets and exchanges, government and electronic identity services, authenticators, messaging apps, browsers and email clients.
“Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud capabilities with broader surveillance and device-control features,” according to ThreatFabric.
The activity dates to at least February 2026, with newer versions appearing in July that added stronger anti-analysis protections, in-memory DEX loading and methods for stealing lock-screen secrets.
PIN theft without a fake banking screen
Manic abuses Android Accessibility and notification permissions to gain extensive control over an infected phone. It can capture passwords, one-time codes, recovery phrases, SMS messages, notifications, files and location data, while also allowing operators to monitor and interact with the screen remotely.
Its PIN-stealing technique is particularly notable because it does not depend on displaying a fake banking interface. When Manic detects a numeric keypad inside a targeted app, it places a transparent layer over the legitimate keys, records the victim’s taps and then passes those taps to the real application through Accessibility services. The banking app continues working normally while the attacker obtains the PIN.
ThreatFabric said, “Manic uses its Accessibility service as a UI keylogger,” with the malware sorting captured information into categories such as lock-screen input, SMS codes, passwords and crypto recovery phrases.
A separate capability can attempt to enter a previously captured PIN or pattern at the Android lock screen, potentially giving an attacker access to the entire device.
An infected phone becomes a relay
Manic’s most unusual feature is its ability to move stolen information through other compromised Android phones.
If an infected phone cannot reach the attackers’ command-and-control server, Manic encrypts collected data and stores it locally. It then searches for nearby infected devices using Wi-Fi Direct, Bluetooth RFCOMM, or Bluetooth Low Energy. If it finds a connected peer, the data can be forwarded through that device to the attackers’ infrastructure. The malware supports up to four relay hops by default.
ThreatFabric said, “removing direct internet access from an infected device does not necessarily prevent data exfiltration, as another infected phone within radio range may act as its gateway.”
What it means for Android users
The combination of financial theft, surveillance and device takeover makes Manic more than a conventional banking trojan. Its ability to exploit legitimate app interfaces also removes one of the visual warning signs users might normally rely on.
The offline relay creates another defensive problem: isolating a compromised phone from the internet may not immediately stop data theft if another infected device is nearby. That makes preventing the initial infection especially important.
Researchers recommend avoiding APKs from unofficial sources, being cautious about granting Accessibility permissions and regularly checking Google Play Protect. ThreatFabric has not disclosed how many devices have been infected, so the scale of the campaign remains unclear.
Also read: Mobile malware isn’t the only threat putting sensitive data at risk, as Alation recently confirmed a cyberattack that has left questions about potential customer exposure and the scope of the incident.





