Manic Android Spyware Uses Fake Utility Apps

The Hacker News · High sophistication
Last updated August 20, 2026

A new Android malware family called “Manic” is being used in real campaigns targeting banking, government identity, and messaging apps, especially in Ukraine and parts of Europe. It spreads through phishing sites and “dropper” apps disguised as legitimate utilities (including a booking-app lure), then steals sensitive data like passwords and one-time codes and can even relay stolen data through nearby infected phones to reach the attacker.

Key findings

  • Manic is being actively used against Ukrainian banks, government/identity services, messaging apps, and also targets Russian and European financial institutions, fintech/crypto, and military-focused communications.
  • Initial access is via “phishing sites and dropper apps impersonating utilities,” including “a booking app lure.”
  • It abuses Android accessibility and notification permissions to capture “lock screen secrets” and steal “passwords, one-time codes, and recovery phrases.”
  • A distinctive feature is a “store-and-forward relay mechanism” that can exfiltrate data through “nearby compromised devices with internet access,” using Wi‑Fi Direct/Bluetooth/BLE and up to “four relay hops by default.”
  • The campaign shows active development in 2026 with “stronger anti-analysis checks” and “lock-secret phishing.”

Who’s being targeted

  • Commonly targeted roles: All employees (Android users), Finance and payments teams, Executives and high-risk users, Travel/operations staff, Security awareness program participants.
  • Affected industries: Banking and financial services, Financial technology (fintech), Cryptocurrency services, Government and digital identity services, Defense and military communications.
  • Attack channels: website.
  • Impersonated: Phone utility/updater service (fake), Booking app provider (fake).

Awareness takeaways

  • Treat any link that asks you to install an Android app from a website as suspicious, use official app stores and approved internal app catalogs only.
  • Be cautious if an app asks for Accessibility or notification permissions; these can enable account takeover and data theft.
  • Do not disable mobile security protections (like Play Protect) when prompted, this is a common step malware uses to stay hidden.
  • Going offline is not a guarantee your data is safe; compromised devices may still leak data via nearby infected phones.

Red flags to watch for

  • Being asked to install an app from a website (not the official app store)
  • Generic “critical update” pressure language
  • App requests powerful permissions (Accessibility/Notifications)
  • App is sideloaded from a link instead of a trusted store
  • Package/app name does not match a known publisher
  • Requests Accessibility access that a booking app would not need
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On your Android phone, a site pops up: “Your phone needs a critical utility update. Download the updater now.” Looks urgent, looks legit. This is how the Manic spyware spreads: phishing sites and dropper apps posing as utilities or even a booking app to ‘confirm your reservation.’ You tap install, and it abuses Accessibility and notification permissions to grab passwords, one‑time codes, even lock‑screen secrets. Here’s the wild part: even if that phone goes offline, Manic can use Wi‑Fi Direct or Bluetooth to hop your data through nearby infected phones, up to four relay hops, until one has internet and ships out your banking and ID info. If any website tells you to download an Android app or update as an APK, stop. Close the tab, and only install apps from the official store or our approved internal catalog.

Similar attacks

Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Insurance Phish Turns OTPs Into Live Account Hijacks

Insurance Phish Turns OTPs Into Live Account Hijacks

Researchers observed insurance-themed phishing that doesn’t just steal passwords, it hijacks accounts in real time while the victim is actively logging in. The attack often starts with sponsored Google ads that lead to convincing fake insurance portals, which immediately prompt victims for one-time…

July 25, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026