"Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud capabilities with broader surveillance and device-control features," ThreatFabric said.
Observed targets and scope
The Dutch security company ThreatFabric, in a technical report shared with The Hacker News, says the Android threat codenamed Manic actively targets Ukrainian banks, government and identity services, and messaging applications, while also affecting Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications. ThreatFabric reported that the malware monitors 169 package IDs covering banks, peer-to-peer (P2P) payment and Buy Now, Pay Later (BNPL) services, cryptocurrency wallets and exchanges, messaging apps, government and eID services, browsers, authenticators, and email clients.
"The target set suggests a blend of banking malware and spyware," ThreatFabric noted, adding that financial fraud appears to be a major objective while the implant's surveillance features enable ongoing monitoring of communications and location.
Distribution and development timeline
ThreatFabric traces activity in the Manic family to February 2026, when the first domain was registered using a fabricated persona. Active development followed: the first wrapper used a booking‑app lure and the implant appeared by the end of May. The researchers observed an operational pause from late June to mid‑July, followed by signs of a second deployment around July 13. A corresponding panel and API went live between July 24 and 28.
The analysis links four APK names to the campaign: tech.intel.dialer.updater and org.honor.secure.helper (wrappers), and org.lenovo.storage.processor and dev.huawei.media.helper (implants). ThreatFabric says the malware is distributed via phishing sites and dropper apps impersonating utilities.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageCapabilities: spying, financial fraud tools, and persistence
Manic combines traditional Android banking‑malware techniques with mobile‑spyware functions. The implant abuses Android accessibility services and notification permissions to capture lock‑screen secrets, present fake overlays, and log user interaction. Noteworthy capabilities listed by ThreatFabric include:
- Intercepting keypad interactions to collect passwords, one‑time codes, and recovery phrases
- Using accessibility services as a "UI keylogger" to classify and record text together with the app in which it appears
- Monitoring the screen and remotely interacting with the device over a WebRTC session
- Recording coordinates and timestamps and enabling device location if not already set
- Taking screenshots; exporting contacts, call history, SMS messages, and notifications; and obtaining the list of installed apps
- Sending SMS to supplied numbers, displaying bogus notifications, deleting files, locking the screen, and attempting to disable Google Play Protect via UI automation
- Removing the implant from the launcher to hide its presence
Manic captures PIN codes by placing a transparent overlay on a numeric keypad, logging the tap position and nearby UI element, then briefly disabling touch interception to replay the tap on the real keypad via accessibility services—allowing the legitimate app to work while the attacker harvests the PIN.
"Persistence relies on background workers, alarms, and the Accessibility and notification services," ThreatFabric said, noting these components maintain command‑and‑control (C2) communication, process commands, upload queued data, and synchronize the offline mesh with periodic execution every 10 to 15 minutes depending on the build.
Offline exfiltration: Wi‑Fi mesh relay and multi‑hop routing
Perhaps Manic's most unusual innovation is a store‑and‑forward relay that exfiltrates data through nearby compromised devices when the source phone lacks internet access. ThreatFabric describes the mechanism as follows: collected files and command results are encrypted and queued locally; the implant searches for infected peers nearby using Wi‑Fi Direct, Bluetooth RFCOMM, or BLE GATT; if it finds a peer, the package is relayed and forwarded toward the C2 server.
The relay supports multi‑hop routes with a default maximum of four hops per queued item and includes relay metadata that carries the current hop count. If a peer cannot be located, the data remains queued and the process retries later. ThreatFabric also observed that an online peer can create a Wi‑Fi Direct group using the same network name and will try to create that group up to three times.
As ThreatFabric points out, this approach means disconnecting a compromised device from the internet does not necessarily prevent data exfiltration: another infected Android device can act as a gateway.
What this means for technologists, affected enterprises, and end users
Technologists and mobile security teams will need to account for accessibility‑service abuse, transparent overlay PIN capture, and the novel offline relay technique; ThreatFabric's indicators include the APK filenames tech.intel.dialer.updater, org.honor.secure.helper, org.lenovo.storage.processor, and dev.huawei.media.helper and the presence of 169 monitored package IDs. Security operators may also watch for periodic background workers executing roughly every 10–15 minutes and for unexpected Wi‑Fi Direct, Bluetooth RFCOMM, or BLE GATT activity that could indicate peer discovery and relay attempts.
Enterprises—particularly banks, fintech and cryptocurrency firms, government services, and organizations using commercial or military‑focused messaging—face combined financial‑fraud and surveillance threats, since Manic is designed both to siphon credentials and to provide real‑time tracking and notifications monitoring.
End users in the affected geographies (the report emphasizes Ukraine as the majority of targets, with additional targets in Russia, Central and Western Europe, and the U.K.) should be aware that phishing sites and dropper apps impersonating utilities are the reported distribution vectors.
"The evolution observed between May and July 2026, including stronger anti‑analysis measures and lock‑secret phishing, indicates that Manic remains under active development and continues to expand its capabilities," ThreatFabric said — a reminder that the threat is not static and that the offline‑relay innovation alters assumptions about what "air‑gapped" or disconnected devices protect against.




