Particle.news

Manic Android Malware Uses Nearby Phones to Exfiltrate Data

Researchers warn this routing lets attackers steal credentials and keep devices under surveillance even when phones appear offline.

Overview

  • ThreatFabric's August 20 report says Manic is an actively developed Android family that blends banking fraud with broad spyware and remote‑control features.
  • The malware stages encrypted files locally and can relay them over Wi‑Fi Direct, Bluetooth RFCOMM or BLE to nearby compromised phones that have internet access, supporting up to four relay hops by default.
  • Manic steals PINs and one‑time codes by placing invisible overlays over numeric keypads, recording tap positions, and replaying taps via Android Accessibility so apps keep working while data is captured.
  • Researchers found Manic monitors at least 169 package IDs across banks, payments, crypto, messengers and government eID apps with a strong focus on Ukrainian targets, and recent July builds added anti‑analysis and in‑memory loading.
  • Users should avoid sideloading APKs, deny Accessibility and notification access to untrusted apps, run Play Protect or mobile security scans, and watch for unexpected Wi‑Fi Direct or Bluetooth activity that could indicate nearby relay traffic.