Manic Android Spyware Uses Fake Utility Apps

The Hacker News · High sophistication
Last updated August 20, 2026

A new Android malware family called “Manic” is being used in real campaigns targeting banking, government identity, and messaging apps, especially in Ukraine and parts of Europe. It spreads through phishing sites and “dropper” apps disguised as legitimate utilities (including a booking-app lure), then steals sensitive data like passwords and one-time codes and can even relay stolen data through nearby infected phones to reach the attacker.

Key findings

  • Manic is being actively used against Ukrainian banks, government/identity services, messaging apps, and also targets Russian and European financial institutions, fintech/crypto, and military-focused communications.
  • Initial access is via “phishing sites and dropper apps impersonating utilities,” including “a booking app lure.”
  • It abuses Android accessibility and notification permissions to capture “lock screen secrets” and steal “passwords, one-time codes, and recovery phrases.”
  • A distinctive feature is a “store-and-forward relay mechanism” that can exfiltrate data through “nearby compromised devices with internet access,” using Wi‑Fi Direct/Bluetooth/BLE and up to “four relay hops by default.”
  • The campaign shows active development in 2026 with “stronger anti-analysis checks” and “lock-secret phishing.”

Who’s being targeted

  • Commonly targeted roles: All employees (Android users), Finance and payments teams, Executives and high-risk users, Travel/operations staff, Security awareness program participants.
  • Affected industries: Banking and financial services, Financial technology (fintech), Cryptocurrency services, Government and digital identity services, Defense and military communications.
  • Attack channels: website.
  • Impersonated: Phone utility/updater service (fake), Booking app provider (fake).

Awareness takeaways

  • Treat any link that asks you to install an Android app from a website as suspicious, use official app stores and approved internal app catalogs only.
  • Be cautious if an app asks for Accessibility or notification permissions; these can enable account takeover and data theft.
  • Do not disable mobile security protections (like Play Protect) when prompted, this is a common step malware uses to stay hidden.
  • Going offline is not a guarantee your data is safe; compromised devices may still leak data via nearby infected phones.

Red flags to watch for

  • Being asked to install an app from a website (not the official app store)
  • Generic “critical update” pressure language
  • App requests powerful permissions (Accessibility/Notifications)
  • App is sideloaded from a link instead of a trusted store
  • Package/app name does not match a known publisher
  • Requests Accessibility access that a booking app would not need
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On your Android phone, a site pops up: “Your phone needs a critical utility update. Download the updater now.” Looks urgent, looks legit. This is how the Manic spyware spreads: phishing sites and dropper apps posing as utilities or even a booking app to ‘confirm your reservation.’ You tap install, and it abuses Accessibility and notification permissions to grab passwords, one‑time codes, even lock‑screen secrets. Here’s the wild part: even if that phone goes offline, Manic can use Wi‑Fi Direct or Bluetooth to hop your data through nearby infected phones, up to four relay hops, until one has internet and ships out your banking and ID info. If any website tells you to download an Android app or update as an APK, stop. Close the tab, and only install apps from the official store or our approved internal catalog.

Similar attacks

NovaCookies Uses Real DocuSign to Steal M365 Sessions

NovaCookies Uses Real DocuSign to Steal M365 Sessions

Researchers report NovaCookies, a phishing-as-a-service toolkit that steals Microsoft 365 session cookies by proxying real logins in real time. The campaigns abuse genuine DocuSign email notifications to deliver a malicious document link that ultimately leads to an attacker-controlled Microsoft 365…

August 26, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Insurance Phish Turns OTPs Into Live Account Hijacks

Insurance Phish Turns OTPs Into Live Account Hijacks

Researchers observed insurance-themed phishing that doesn’t just steal passwords, it hijacks accounts in real time while the victim is actively logging in. The attack often starts with sponsored Google ads that lead to convincing fake insurance portals, which immediately prompt victims for one-time…

July 25, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Apollo Breach Tied to IT Support Impersonation

Apollo Breach Tied to IT Support Impersonation

Apollo Global Management disclosed a data breach after attackers used social engineering to gain unauthorized access to certain cloud platforms over several days in July. The attackers obtained sensitive personal data (including Social Security numbers), highlighting how stolen credentials and…

August 25, 2026
Fake Bank Sites ‘Play Dead’ to Steal Logins

Fake Bank Sites ‘Play Dead’ to Steal Logins

Researchers documented a real phishing method where attackers push fake bank sites up in search results, then show different content depending on how a person arrived. If someone clicks from a poisoned search result, the site shows a realistic bank login page to steal credentials; if security teams…

August 24, 2026