A newly documented Android threat named Manic is redefining what a single piece of mobile malware can do, blending classic banking-fraud tools with the kind of surveillance capability normally associated with nation-state spyware.
Researchers at ThreatFabric’s Mobile Threat Intelligence team have been tracking the family since infrastructure first appeared in February 2026, and their findings paint a picture of a rapidly maturing fraud platform that treats a victim’s phone as both a wallet to drain and a listening post to exploit.
Manic isn’t chasing a narrow slice of victims. It actively monitors 169 distinct package IDs spanning banking apps, payment platforms, cryptocurrency wallets and exchanges, government eID services, authenticator apps, messengers, browsers, and email clients.
Manic Malware: New Android Threat Blends Banking Trojan
Ukraine sits at the center of the targeting, covering its banks, state identity systems, and messaging platforms, but the net extends outward to Russian and Central/Western European banks, UK financial institutions, and global fintech and crypto services.
The presence of military-focused communication apps alongside consumer banking targets is telling: this isn’t purely a money-grab operation; it’s built to harvest financial data and intelligence in the same sweep.

Once installed, Manic requests Accessibility and notification access, the two permissions that unlock nearly everything else. From there, it functions as an intelligent UI keylogger, classifying every captured input lock codes, seed phrases, one-time passcodes, passwords, or ordinary text before logging it with app context and timestamps.
Live remote-control sessions over WebRTC let an operator watch and interact with the screen in real time, while the screen is hidden behind fake updates or black screens that also mask permission prompts.
The July 2026 build went further, stripping the implant’s icon from the launcher entirely, so it activates only through a wrapper or deep link, making detection by an unsuspecting victim nearly impossible.

Manic’s most technically distinctive feature is how it steals PINs. Rather than deploying a fake login screen, its “pinPadOverlay” function detects a target app’s real numeric keypad, transparently intercepts each tap, logs the coordinates, then instantly replays that same tap so the legitimate app functions normally.
A companion “autoEnterPin” capability operates directly on the Android lock screen, attempting to re-enter a previously harvested credential. Together they let operators steal PINs invisibly during normal use and later unlock the device outright.
“What makes Manic dangerous isn’t any single feature it’s the workflow. Credential theft, live device control, and covert exfiltration are stitched into one continuous fraud pipeline, which is exactly the operational maturity we’d expect from a well-funded criminal group rather than a hobbyist project.”
Perhaps the most novel element is Manic’s store-and-forward exfiltration mesh. When a compromised phone can’t reach command-and-control directly, it encrypts stolen data with AES-GCM, queues it locally, and searches for another infected device nearby via Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT.
If a peer with internet access is found, the package hops through up to four relays toward the operators’ servers by default. This means cutting off a single infected phone’s connectivity does not guarantee data stays contained.
Manic’s rapid evolution since May 2026, adding anti-analysis checks, in-memory DEX loading, and lock-secret phishing, signals a threat still actively under development and likely to expand its reach well beyond its current Ukraine-centric focus.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.