A new Android malware family called “Manic” is being used in real campaigns targeting banking, government identity, and messaging apps, especially in Ukraine and parts of Europe. It spreads through phishing sites and “dropper” apps disguised as legitimate utilities (including a booking-app lure), then steals sensitive data like passwords and one-time codes and can even relay stolen data through nearby infected phones to reach the attacker.
Key findings
- Manic is being actively used against Ukrainian banks, government/identity services, messaging apps, and also targets Russian and European financial institutions, fintech/crypto, and military-focused communications.
- Initial access is via “phishing sites and dropper apps impersonating utilities,” including “a booking app lure.”
- It abuses Android accessibility and notification permissions to capture “lock screen secrets” and steal “passwords, one-time codes, and recovery phrases.”
- A distinctive feature is a “store-and-forward relay mechanism” that can exfiltrate data through “nearby compromised devices with internet access,” using Wi‑Fi Direct/Bluetooth/BLE and up to “four relay hops by default.”
- The campaign shows active development in 2026 with “stronger anti-analysis checks” and “lock-secret phishing.”
Who’s being targeted
- Commonly targeted roles: All employees (Android users), Finance and payments teams, Executives and high-risk users, Travel/operations staff, Security awareness program participants.
- Affected industries: Banking and financial services, Financial technology (fintech), Cryptocurrency services, Government and digital identity services, Defense and military communications.
- Attack channels: website.
- Impersonated: Phone utility/updater service (fake), Booking app provider (fake).
Awareness takeaways
- Treat any link that asks you to install an Android app from a website as suspicious, use official app stores and approved internal app catalogs only.
- Be cautious if an app asks for Accessibility or notification permissions; these can enable account takeover and data theft.
- Do not disable mobile security protections (like Play Protect) when prompted, this is a common step malware uses to stay hidden.
- Going offline is not a guarantee your data is safe; compromised devices may still leak data via nearby infected phones.
Red flags to watch for
- Being asked to install an app from a website (not the official app store)
- Generic “critical update” pressure language
- App requests powerful permissions (Accessibility/Notifications)
- App is sideloaded from a link instead of a trusted store
- Package/app name does not match a known publisher
- Requests Accessibility access that a booking app would not need
Read the video transcript
On your Android phone, a site pops up: “Your phone needs a critical utility update. Download the updater now.” Looks urgent, looks legit. This is how the Manic spyware spreads: phishing sites and dropper apps posing as utilities or even a booking app to ‘confirm your reservation.’ You tap install, and it abuses Accessibility and notification permissions to grab passwords, one‑time codes, even lock‑screen secrets. Here’s the wild part: even if that phone goes offline, Manic can use Wi‑Fi Direct or Bluetooth to hop your data through nearby infected phones, up to four relay hops, until one has internet and ships out your banking and ID info. If any website tells you to download an Android app or update as an APK, stop. Close the tab, and only install apps from the official store or our approved internal catalog.