← Terug naar overzicht

A new Android malware strain called Manic has been discovered actively targeting Ukrainian banks, government agencies, identity services, and messaging apps, as well as Russian and European financial institutions, global fintech and cryptocurrency platforms, and military communications. Manic combines capabilities of both banking malware and mobile spyware, enabling financial fraud alongside surveillance. A particularly notable feature is its ability to exfiltrate data from offline phones by leveraging nearby infected devices, suggesting advanced peer-to-peer or proximity-based communication mechanisms. The malware represents a sophisticated threat actor operation with geopolitical dimensions, given its focus on Ukrainian and Russian targets amid ongoing conflict. Its dual-purpose nature makes it especially dangerous for both financial and national security contexts.

Technical details

Manic is an Android malware family that combines banking malware and spyware capabilities. It targets 169 package IDs across Ukrainian banks, government/identity services, messaging apps, Russian and European financial institutions, fintech, cryptocurrency services, and military communications. First domain registered February 2026; first wrapper (booking app lure) and implant appeared by end of May 2026; second deployment emerged around July 13 with stronger anti-analysis checks and lock-screen phishing. Panel and API went live July 24-28. Distribution is via phishing sites and dropper apps impersonating utilities. Key capabilities include: abusing Android Accessibility Services and notification permissions; UI keylogging to capture passwords, OTPs, and recovery phrases; transparent overlay atop legitimate numeric keypads to capture PINs without displaying a fake interface; WebRTC-based remote screen monitoring and device interaction; location tracking; screenshot capture; exfiltration of contacts, call logs, SMS, notifications; sending SMS; displaying bogus notifications; disabling Google Play Protect via UI automation; screen locking; file deletion; and hiding the implant from the launcher. Most notably, Manic implements a store-and-forward Wi-Fi mesh relay mechanism: collected data is encrypted and queued locally, then relayed via Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT to a nearby infected peer device that has internet access, forwarding data to the C2 server with up to four relay hops by default. This allows data exfiltration even when the source device is offline. Persistence is maintained via background workers, alarms, Accessibility services, and notification services, with periodic execution every 10-15 minutes.

Mitigation steps

1. Avoid sideloading APKs from untrusted sources, phishing sites, or dropper apps impersonating utilities. 2. Keep Google Play Protect enabled and monitor for attempts to disable it via UI automation. 3. Review and restrict Accessibility Service permissions granted to apps, especially to unknown or suspicious applications. 4. Monitor for suspicious APK package names: tech.intel.dialer.updater, org.honor.secure.helper, org.lenovo.storage.processor, dev.huawei.media.helper. 5. Be aware that disconnecting a device from the internet does not prevent data exfiltration, as Manic can relay data through nearby infected devices via Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT. 6. Monitor for unusual use of Wi-Fi Direct, Bluetooth, or BLE communications on managed devices. 7. Deploy mobile threat defense (MTD) solutions capable of detecting overlay attacks, keylogging via accessibility services, and anomalous peer-to-peer mesh communication. 8. Educate users about phishing sites and fake utility apps used to distribute the malware. 9. Organizations in Ukraine, Russia, Europe, and the UK with users of banking, fintech, crypto, government identity, or military messaging apps should prioritize monitoring and alerting for the identified IOCs.

Affected products

  • Android devices (banking apps
  • Central/Western European
  • Global fintech and cryptocurrency services
  • Military-focused communications applications
  • P2P payment/BNPL services
  • Russian and European financial institutions
  • Ukrainian banks and government/identity services
  • also Russian
  • and UK apps)
  • authenticators
  • browsers
  • cryptocurrency wallets and exchanges
  • email clients — primarily Ukrainian
  • government and eID services
  • messaging apps

IOC's

Package name (Wrapper): tech.intel.dialer.updater, Package name (Wrapper): org.honor.secure.helper, Package name (Implant): org.lenovo.storage.processor, Package name (Implant): dev.huawei.media.helper, Malware family name: Manic, First domain registered: February 2026 (fabricated persona), Wi-Fi Direct group network name: consistent/same across all retained builds, C2 communication interval: every 10-15 minutes, Default relay hop limit: 4 hops, Maximum Wi-Fi Direct group creation attempts: 3

Categories

  • Data Breach & Exfiltration
  • Mobile & IoT
  • Ransomware & Malware