Manic Android Malware Steals PINs and Relays Data via Nearby Infected Devices
A newly documented Android malware called Manic, analyzed by ThreatFabric and published on August 20, 2026, combines banking malware and spyware capabilities targeting 169 apps across banking, government, cryptocurrency, and authentication categories. The malware tricks users into granting Accessibility and Notification Access permissions, then uses transparent overlays on numeric keypads to silently capture PINs, OTPs, and recovery phrases without disrupting normal app function. Beyond credential theft, Manic collects SMS messages, files, screenshots, and location data, and can also enable remote device control via WebRTC. When a direct internet connection to its command-and-control server is unavailable, the malware encrypts stolen data and relays it through up to four hops across nearby infected devices using Wi-Fi Direct, Bluetooth RFCOMM, and BLE GATT. The initial distribution method has not yet been confirmed, but mitigations include blocking unmanaged app installs, restricting Accessibility permissions, and disabling unnecessary Bluetooth and Wi-Fi Direct.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in