Manic Turns Android Phones into Silent Banking and Spy Networks 

Researchers at ThreatFabric have tracked Manic, a new banking malware campaign targeting Android users in Ukraine and across Europe.

Since February 2026, researchers at ThreatFabric have tracked Manic, a new banking malware campaign targeting Android users in Ukraine and across Europe through phishing apps, using spyware tools, PIN theft, remote control, and a device-to-device Wi-Fi relay system for exfiltration. 

Other than stealing logins, Manic can watch screens, track location and move stolen data through nearby infected phones, making a compromised device harder to isolate. 

Manic Blends Financial Fraud with Spyware 

ThreatFabric describes Manic as banking malware under active development.  

“Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud capabilities with broader surveillance and device-control features,” the company declared.  

Its infrastructure dates to February. 

The Android malware monitors 169 package IDs tied to banks, payment services, crypto platforms, messaging apps, government identity tools and authenticators. Most targets are Ukrainian, although apps elsewhere in Europe and Russia also appear. 

July builds added stronger anti-analysis checks and lock-screen secret phishing. The changes matter for banking malware detection, because defenders are dealing with a threat that is still changing. 

Manic spreads through phishing sites and dropper apps posing as utilities. After installation, it abuses Android accessibility and notification permissions, letting the banking malware capture text, hide activity and remotely control the phone. 

Unlike traditional cryptoware, usually linked to locking files for payment, Manic stays quiet. It can export contacts, calls, SMS messages and notifications, take screenshots, track location, and send messages. 

Its malware banking functions can intercept keypad actions and collect passwords, one-time codes, and recovery phrases. It can also create fake notifications, delete files, lock thescreen,n and try to disable Google Play Protect. 

“The target set suggests a blend of banking malware and spyware,” ThreatFabric noted. “Financial fraud appears to be a major objective, with coverage spanning banks, payment services, cryptocurrency exchanges and wallets, government identity apps, and authenticators.” 

A PIN Attack and an Offline Escape Route 

Manic can steal PINs without showing a fake banking page. It places a transparent layer over the real keypad and records each tap. That complicates banking malware detection, because the victim keeps using the legitimate app. 

Manic also uses accessibility as a “UI keylogger,” classifying passwords, SMS codes and recovery phrases. That moves it into crypto wallet malware territory, where one stolen recovery phrase can give attackers control of digital assets. 

A second cryptoware concern is how much Manic can gather without disrupting the phone. It is not classic file-encrypting malware, but it combines financial theft with surveillance. 

Android malware supports live remote control through WebRTC. Operators can watch and interact with the device, while the implant can hide itself from the launcher and conceal activity behind fake screens. 

“Persistence relies on background workers, alarms, and the Accessibility and notification services,” ThreatFabric said. “These components maintain C2 communication, process commands, upload queued data, and synchronize the offline mesh, with periodic execution every 10 to 15 minutes depending on the build.” 

The unusual part of Manic’s malware banking design is its relay system. If a phone cannot reach the command-and-control server, encrypted data can pass to another infected device through Wi-Fi Direct, Bluetooth RFCOMM or BLE GATT. 

For mobile threat intelligence teams, this changes the response. Disconnecting one phone may not stop exfiltration if another compromised device nearby can act as a gateway. Manic supports multi-hop routes, with four hops set by default. 

This challenges leading mobile app risk intelligence services for mobile threat intelligence, because defenders may need to watch local device-to-device traffic as well as direct links to attacker infrastructure. An offline phone may still leak stolen data. 

“The evolution observed between May and July 2026, including stronger anti-analysis measures and lock-secret phishing, indicates that Manic remains under active development and continues to expand its capabilities,” ThreatFabric said. 

Google said it found no affected apps on Google Play.  

Based on their current detection, no apps containing this malware are found on Google Play. Android users are automatically protected against known versions of this malware by Google Play Protect, which is by default on Android devices with Google Play Services. 

The main exposure remains with phishing pages and unofficial APK downloads. Manic shows how banking malware is becoming a wider surveillance platform, combining financial theft, remote access and nearby-device relays.  

Disconnecting a compromised phone may no longer be enough. 


Join our WhatsApp Channel WhatsApp Channel