
Security researchers have documented a new Android malware family named Manic that is targeting users in multiple European countries, with a particular focus on Ukraine. According to an analysis by mobile security firm ThreatFabric, published by BleepingComputer, the malware has been active since at least February and combines spyware, banking fraud, and remote control capabilities.
Manic abuses Android's Accessibility service to perform overlay attacks on numeric keypads in legitimate applications. It places transparent overlays over these keypads, captures the victim's taps, and replays them through the Accessibility API. This technique lets the legitimate apps continue functioning normally while the malware records the input. Once the victim grants Accessibility and notification access permissions, Manic can capture the lock screen PIN or password, intercept SMS messages and notifications, collect files and location data, monitor the screen, and provide remote control to operators through WebRTC sessions.
The malware's keylogging is highly structured. ThreatFabric describes the Accessibility service as a 'UI keylogger' that classifies captured text before recording it. It distinguishes between lock-screen input, recovery-phrase candidates, four-to-six-digit SMS codes, passwords, long messages, email logins, and ordinary text. This sorting makes the stolen information more readily usable by the attackers.
A distinctive feature of Manic is its fallback data exfiltration mechanism. If a compromised device cannot reach its command-and-control (C2) server, the malware attempts to send encrypted data through other nearby infected devices. According to ThreatFabric, it first tries an established Wi-Fi Direct peer, then queries Bluetooth and Bluetooth Low Energy peers to determine whether they have internet connectivity. The malware can also use multi-hop routes, with newly queued items configured by default to allow up to four relay hops. This approach allows data exfiltration even from offline devices, provided another infected phone is within Wi-Fi or Bluetooth range.
The malware targets at least 169 applications, including banking, government/eID, payment, cryptocurrency wallet, messaging, and authenticator/two-factor authentication apps. Although Manic has been observed across Central and Western Europe, the United Kingdom, and Russia, its primary focus appears to be Ukrainian banking and government/eID applications, along with global fintech and cryptocurrency services.
The exact infection vector remains unknown. Researchers noticed in late May the use of a wrapper that delivered the main payload to victims, followed by an expansion of the existing infrastructure in the following months. In July, attacks used an updated wrapper with stronger anti-analysis checks and in-memory DEX loading, and a new panel and API were rolled out.
To reduce risk, users are advised to avoid downloading APKs from obscure or unofficial portals, deny Accessibility permissions unless requested by a trusted application, and regularly run Google Play Protect scans to detect and remove known malware.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST

