THREATFABRIC'S Mobile Threat Intelligence team has identified a new Android malware named Manic, active since February 2026. Manic combines banking fraud and spyware capabilities, primarily targeting apps related to Ukrainian banks and government services, as well as European and Russian financial institutions. The malware monitors 169 different apps, extracting sensitive data like PINs and passwords via UI keylogging methods.
A distinct feature is its store-and-forward relay mechanism, allowing data exfiltration even when the device is offline by leveraging nearby infected devices. Manic also enables remote control of the infected device and utilizes advanced techniques to hide its presence. Detection methods focus on unusual Accessibility service requests and unexpected Bluetooth or Wi-Fi Direct connections.