Overview
- ThreatFabric published a technical report Thursday, Aug 20, 2026, showing Manic stages collected data in AES‑GCM encrypted queues and forwards it over Wi‑Fi Direct, Bluetooth RFCOMM or BLE to other compromised phones, with a default four‑hop relay limit.
- The malware combines banking fraud and broad spyware functions, abusing Android Accessibility and notification access to log text, capture PINs with invisible keypad overlays, replay taps to keep apps working, and remotely view or control devices via WebRTC.
- Manic watches roughly 169 package IDs across banks, payment services, crypto wallets, government eID apps, messaging and authenticator tools, with a primary focus on Ukrainian targets and additional coverage in Russia and Central and Western Europe.
- Researchers traced the campaign to infrastructure registered in February 2026 and observed delivery via phishing sites, wrapper APKs and droppers; July builds added stronger anti-analysis checks, in‑memory DEX loading, lock‑screen phishing and a new C2 panel and API.
- Defenders are urged to deny Accessibility grants to untrusted apps, avoid installing APKs from unofficial sources, monitor unexpected Wi‑Fi Direct or Bluetooth groups, run Play Protect scans, and note that simply cutting a phone’s internet may not stop data loss.