Manic Android Malware Added a Nearby-Phone Leak Path

ThreatFabric found that Manic, an Android malware family active since at least February, can steal data through nearby infected phones even when the victim device cannot reach its own command server. The malware also targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator apps, with Ukraine as the main focus in the campaign ThreatFabric examined. Manic uses accessibility permissions and fake keypad overlays to capture PINs, passwords, SMS codes, notifications, files, location data, and screen activity. If the phone cannot contact command-and-control directly, it encrypts the stolen data and hands it off over Wi‑Fi Direct or Bluetooth to another infected handset that can send it onward, which means blocking one device’s network path may not stop the leak. For Android fleets that carry banking, identity, or two-factor approvals, the exposure is not just a single compromised handset. Nearby infected phones can become a relay mesh, so a device that looks isolated can still feed data out through another handset within radio range.

Part of the PlainSec briefing for 2026-08-21

Editions

Sources