ThreatFabric researchers reported a new Android malware strain, Manic, that is being actively distributed in the wild and primarily targets users in Ukraine while also reaching victims across Europe and beyond. The malware combines mobile banking trojan behavior with spyware and remote-control functions, targeting at least 169 applications tied to banks, government and eID services, payment platforms, cryptocurrency wallets, messaging tools, authenticator apps, and military-focused communications. Reported targets include Ukrainian banks and state services, as well as Russian and European financial institutions and global fintech and crypto services.
Manic abuses Android Accessibility services and uses transparent keypad overlays to capture credentials and user input while legitimate apps continue to operate, enabling theft of PINs, passwords, SMS codes, and other sensitive data. Researchers said the malware also features an unusual fallback exfiltration method that sends encrypted stolen data through nearby infected devices over Wi-Fi Direct or Bluetooth, including multi-hop routing when a device lacks direct internet access. The campaign has reportedly been active since at least February, with wrapper-based payload delivery observed in late May and more advanced anti-analysis and in-memory DEX loading added in July.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
After initial Manic efforts were abandoned from late June to mid-July 2026, signs of a second deployment emerged around July 13. This newer iteration included stronger anti-analysis features and lock-screen secret phishing capabilities.
In July, researchers observed an updated Manic wrapper that added stronger anti-analysis checks and in-memory DEX loading. They also saw a new operator panel and API associated with the campaign.
Researchers observed a wrapper delivering the main Manic payload to victims in late May. They also noted subsequent expansion of the malware's supporting infrastructure after this delivery stage was seen.
ThreatFabric researchers observed the Android malware family Manic operating in the wild since at least February. The malware combines banking-fraud, spyware, and remote-control capabilities and primarily targets users in Ukraine while also reaching other European countries and Russia.
ThreatFabric identified Manic as a new Android threat and reported that it targets at least 169 banking, government/eID, payment, cryptocurrency, messaging, and authenticator applications. The analysis highlighted its blend of banking malware and spyware behavior, including a relay-based fallback exfiltration mechanism using nearby infected devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcemalware.news
Open sourcethreatfabric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.