Manic Android Spyware Uses Fake Utility Apps

The Hacker News · High sophistication
Last updated August 20, 2026

A new Android malware family called “Manic” is being used in real campaigns targeting banking, government identity, and messaging apps, especially in Ukraine and parts of Europe. It spreads through phishing sites and “dropper” apps disguised as legitimate utilities (including a booking-app lure), then steals sensitive data like passwords and one-time codes and can even relay stolen data through nearby infected phones to reach the attacker.

Key findings

  • Manic is being actively used against Ukrainian banks, government/identity services, messaging apps, and also targets Russian and European financial institutions, fintech/crypto, and military-focused communications.
  • Initial access is via “phishing sites and dropper apps impersonating utilities,” including “a booking app lure.”
  • It abuses Android accessibility and notification permissions to capture “lock screen secrets” and steal “passwords, one-time codes, and recovery phrases.”
  • A distinctive feature is a “store-and-forward relay mechanism” that can exfiltrate data through “nearby compromised devices with internet access,” using Wi‑Fi Direct/Bluetooth/BLE and up to “four relay hops by default.”
  • The campaign shows active development in 2026 with “stronger anti-analysis checks” and “lock-secret phishing.”

Who’s being targeted

  • Commonly targeted roles: All employees (Android users), Finance and payments teams, Executives and high-risk users, Travel/operations staff, Security awareness program participants.
  • Affected industries: Banking and financial services, Financial technology (fintech), Cryptocurrency services, Government and digital identity services, Defense and military communications.
  • Attack channels: website.
  • Impersonated: Phone utility/updater service (fake), Booking app provider (fake).

Awareness takeaways

  • Treat any link that asks you to install an Android app from a website as suspicious, use official app stores and approved internal app catalogs only.
  • Be cautious if an app asks for Accessibility or notification permissions; these can enable account takeover and data theft.
  • Do not disable mobile security protections (like Play Protect) when prompted, this is a common step malware uses to stay hidden.
  • Going offline is not a guarantee your data is safe; compromised devices may still leak data via nearby infected phones.

Red flags to watch for

  • Being asked to install an app from a website (not the official app store)
  • Generic “critical update” pressure language
  • App requests powerful permissions (Accessibility/Notifications)
  • App is sideloaded from a link instead of a trusted store
  • Package/app name does not match a known publisher
  • Requests Accessibility access that a booking app would not need
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On your Android phone, a site pops up: “Your phone needs a critical utility update. Download the updater now.” Looks urgent, looks legit. This is how the Manic spyware spreads: phishing sites and dropper apps posing as utilities or even a booking app to ‘confirm your reservation.’ You tap install, and it abuses Accessibility and notification permissions to grab passwords, one‑time codes, even lock‑screen secrets. Here’s the wild part: even if that phone goes offline, Manic can use Wi‑Fi Direct or Bluetooth to hop your data through nearby infected phones, up to four relay hops, until one has internet and ships out your banking and ID info. If any website tells you to download an Android app or update as an APK, stop. Close the tab, and only install apps from the official store or our approved internal catalog.

Similar attacks

NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Insurance Phish Turns OTPs Into Live Account Hijacks

Insurance Phish Turns OTPs Into Live Account Hijacks

Researchers observed insurance-themed phishing that doesn’t just steal passwords, it hijacks accounts in real time while the victim is actively logging in. The attack often starts with sponsored Google ads that lead to convincing fake insurance portals, which immediately prompt victims for one-time…

July 25, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026
AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026