Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
-
A newly identified Android threat, dubbed Manic, is actively targeting financial institutions, government services, and messaging platforms. According to recent analysis, the malware is being deployed against Ukrainian banks and identity services, as well as Russian and European financial entities, global fintech and cryptocurrency platforms, and military-focused communications apps.
Manic sits at the intersection of Android banking malware and mobile spyware, blending financial-fraud capabilities with surveillance-grade data collection. Its most distinctive feature is its ability to exfiltrate data from devices that are completely offline, by leveraging nearby infected handsets as relay points. This peer-to-peer communication method allows the malware to bridge air-gapped or disconnected devices, ensuring stolen credentials and sensitive data eventually reach the threat actor’s command infrastructure.
Key technical behaviors reported include:
- Targeting of banking, government, and messaging apps for credential theft via overlay attacks.
- Collection of SMS messages, call logs, and device information.
- Offline data exfiltration through encrypted local network propagation, using other compromised devices to siphon data onward.
- Focus on both traditional banking trojans and espionage-style data gathering.
The campaign appears to be active, with a particular emphasis on geopolitical targets in Eastern Europe and the broader financial sector. No specific CVE or patch identifiers were listed in the original report, and the malware is likely distributed via sideloaded APKs or malicious campaigns rather than a specific OS-level vulnerability.
Organizations in the affected regions should review their mobile device management policies, restrict sideloading, and monitor for unusual local network traffic between Android devices.
Source: The Hacker News
Is your organization’s mobile fleet exposed to peer-to-peer exfiltration risks, and what controls have you implemented to detect local network chatter between devices?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login