Particle.news
Download on the App Store

Manic Android Malware Can Exfiltrate Data Through Nearby Infected Phones

Researchers say an encrypted multi-hop relay over Bluetooth/Wi‑Fi Direct lets operators pull credentials and device files from phones with no internet.

Overview

  • ThreatFabric and other security outlets published technical findings on Thursday that describe Manic as an actively developed Android threat combining banking fraud, spyware and remote device control.
  • When a device lacks internet access Manic stages stolen items in AESGCM encrypted queues and forwards them through nearby compromised phones using Wi‑Fi Direct, Bluetooth RFCOMM or BLE with up to four relay hops.
  • The implant abuses Android Accessibility and notification permissions, uses invisible overlays to record PIN taps while replaying them so apps work normally, and can capture SMS one‑time codes, recovery phrases, screenshots and location.
  • Researchers traced infrastructure back to February 2026 and observed distribution by phishing sites and dropper/wrapper APKs plus July updates that added anti‑analysis checks, in‑memory DEX loading, lock‑secret phishing and launcher hiding.
  • Defenders should treat sideloaded APKs and unexpected Accessibility grants as high risk, monitor unusual Bluetooth or Wi‑Fi Direct peer activity, run Play Protect or mobile EDR, and not rely solely on cutting a phone’s internet to stop data leakage.