Researchers identified Manic, an Android malware family combining banking-trojan, spyware, and remote-access functions. It abuses Accessibility services, a transparent keyboard overlay, SMS access, and notification access to capture credentials, banking details, and one-time authentication codes; it can also conceal operator activity with a black screen or fake system-update display while performing actions on the victim device.
Manic’s distinguishing capability is mesh-style data exfiltration: offline infected phones can encrypt and relay stolen data over Wi-Fi or Bluetooth through as many as four nearby compromised devices until a node reaches the internet. Infrastructure linked to the campaign reportedly appeared in February 2026 and samples were identified in late May, with banking-app users in multiple European countries, including Russia, Ukraine, and the United Kingdom, among the targets.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
The earliest identified samples of the Manic Android banking trojan, spyware, and remote-access malware family appeared in late May 2026.
Researchers traced the attacker infrastructure supporting the Manic Android malware campaign to February 2026.
After the earliest samples emerged, Manic's operators improved the malware's mechanisms for evading detection on infected devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.