{"investigation":{"slug":"manic-android-banking-trojan-crypto-wallet-targeting-malware","entity_name":"Manic (Android Banking Trojan / Crypto-Wallet-Targeting Malware)","trust_score":1,"severity_base":null,"score_modifier":0,"confidence":0.8,"status":"draft","content_type":"investigation","summary":"Manic is an active Android malware family, publicly disclosed by the Dutch mobile-threat intelligence firm ThreatFabric on August 20, 2026 and separately covered by Kaspersky, that combines banking-trojan credential theft with spyware and full device-takeover capabilities. It monitors 169 Android app package IDs — including banks, payment apps, cryptocurrency wallets and exchanges, government eID services, authenticator apps, messengers, browsers and email clients — and is notable for an invisible-overlay keystroke capture technique paired with Accessibility-service replay, plus a novel offline Wi-Fi/Bluetooth mesh exfiltration mechanism that relays stolen data through other nearby infected phones even when the source device has no internet access. Manic is not a company or product to be trusted but an active criminal threat; it is indexed here as a risk entity so that crypto holders on Android can recognize and avoid it.","sections":[{"content":"Manic is the name assigned by ThreatFabric's Mobile Threat Intelligence team to a previously undocumented Android malware family that the firm describes as sitting \"at the intersection of Android banking malware and mobile spyware,\" combining financial-fraud capabilities with broader surveillance and device-control features. ThreatFabric classifies it as a hybrid fraud platform built for device takeover (DTO) operations. Kaspersky independently profiled the same malware family on its official blog, confirming its core capabilities. No specific threat-actor group has been publicly attributed to Manic by either research organization.","heading":"Identification and Classification","sources":[{"url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware","name":"ThreatFabric: Manic — Blend between Banking Malware & Spyware","type":"research","credibility":2},{"url":"https://www.kaspersky.com/blog/manic-android-trojan/56323/","name":"Kaspersky Daily: This Android malware steals banking credentials even without an internet connection","type":"research","credibility":2}],"severity":"high"},{"content":"Manic monitors 169 Android app package IDs, a target list that spans banks, payment services, buy-now-pay-later and remittance apps, cryptocurrency exchanges and wallets, government/eID services, authenticator apps, messaging apps, browsers, and email clients, according to ThreatFabric's technical disclosure and corroborating coverage. Multiple outlets, including BleepingComputer and The Hacker News, independently confirmed that the target list includes cryptocurrency wallet and exchange applications alongside traditional banking apps, meaning the malware poses a direct, active threat to Android users' crypto holdings, not merely to fiat bank accounts. Specific package names for the crypto wallet/exchange subset were not published in the sources reviewed; ThreatFabric's full technical report may contain the complete list but was not independently obtained for this dossier.","heading":"Crypto Wallet and Exchange Targeting","sources":[{"url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware","name":"ThreatFabric: Manic — Blend between Banking Malware & Spyware","type":"research","credibility":2},{"url":"https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/","name":"BleepingComputer: New Manic Android malware can exfiltrate data through nearby devices","type":"news_article","credibility":2},{"url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html","name":"The Hacker News: Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices","type":"news_article","credibility":2},{"url":"https://www.esecurityplanet.com/threats/news-manic-android-malware-device-relay-data-theft/","name":"eSecurity Planet: New Manic Android Malware Uses Offline Networks to Drain Bank Accounts","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Manic's credential-theft method is designed to avoid displaying a fake login screen, a departure from typical Android banking trojans. When a targeted app (bank, wallet, or exchange) presents a numeric keypad or login form, Manic lays a transparent overlay directly over the real keys. As the victim taps, the malware records the tap position and key value, briefly disables its own touch interception, and then uses Android's Accessibility service to replay the same keystroke into the legitimate app's real interface — so the victim sees only the genuine app and no fake overlay is visibly rendered. ThreatFabric states Manic \"uses its Accessibility service as a UI keylogger,\" capable of distinguishing and separately classifying captured data such as lock-screen input, recovery-phrase candidates (i.e., crypto wallet seed phrases), four-to-six-digit SMS one-time codes, passwords, and email logins, along with the app name, timestamp, and whether the value was auto-filled. This design is intended to defeat anti-fraud checks in banking and wallet apps that rely on detecting overlay attacks or screen-recording.","heading":"Invisible Overlay Keystroke Capture and Accessibility-Service Replay","sources":[{"url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware","name":"ThreatFabric: Manic — Blend between Banking Malware & Spyware","type":"research","credibility":2},{"url":"https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/","name":"BleepingComputer: New Manic Android malware can exfiltrate data through nearby devices","type":"news_article","credibility":2},{"url":"https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html","name":"Security Affairs: Manic — The Android Malware That Exfiltrates Data Even When the Phone Is Offline","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Beyond credential theft, Manic provides operators with live remote control of infected devices via WebRTC sessions, allowing real-time screen viewing and interaction, reportedly with screen-masking features to conceal fraudulent activity from the device owner. The July 2026 update added the ability to attempt device unlock using previously captured PINs or unlock patterns (\"lock-screen secret theft\"), in-memory DEX loading (allowing the malicious payload to be loaded without writing a detectable file to disk), and stronger anti-analysis/anti-emulation protections designed to evade security researchers and automated sandboxes. The malware also harvests SMS messages, push notifications, files, and location data, and provides visibility into two-factor authentication flows by reading authenticator-app notifications and SMS codes.","heading":"Device Takeover, Remote Control, and Lock-Screen Secret Theft","sources":[{"url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware","name":"ThreatFabric: Manic — Blend between Banking Malware & Spyware","type":"research","credibility":2},{"url":"https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html","name":"Security Affairs: Manic — The Android Malware That Exfiltrates Data Even When the Phone Is Offline","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Manic's most distinctive feature is a \"store-and-forward relay mechanism\" that lets it exfiltrate stolen data even when the infected device has no internet connectivity. The malware encrypts collected data and stores it locally, then scans for other nearby infected Android devices using Wi-Fi Direct, Bluetooth RFCOMM, or Bluetooth Low Energy (BLE) GATT. If it finds one, it hands the encrypted data package to that device, which forwards it toward the attackers' command-and-control server (directly, or via a further hop), supporting relay chains of up to four hops. This proximity-based mesh technique is designed to defeat conventional network-based defenses such as disconnecting a suspected-infected phone from the internet, since data can still leave the device via short-range radio to another compromised phone that does have connectivity. Researchers describe this as a genuinely novel technique not previously documented in consumer Android banking malware.","heading":"Offline Wi-Fi/Bluetooth Mesh Exfiltration","sources":[{"url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware","name":"ThreatFabric: Manic — Blend between Banking Malware & Spyware","type":"research","credibility":2},{"url":"https://www.kaspersky.com/blog/manic-android-trojan/56323/","name":"Kaspersky Daily: This Android malware steals banking credentials even without an internet connection","type":"research","credibility":2},{"url":"https://www.esecurityplanet.com/threats/news-manic-android-malware-device-relay-data-theft/","name":"eSecurity Planet: New Manic Android Malware Uses Offline Networks to Drain Bank Accounts","type":"news_article","credibility":2},{"url":"https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/","name":"BleepingComputer: New Manic Android malware can exfiltrate data through nearby devices","type":"news_article","credibility":2}],"severity":"high"},{"content":"Manic's observed targeting is concentrated on Ukraine, including Ukrainian banking, government/eID, and military-focused messaging applications. Secondary targeting covers Russia and a broad swath of Europe — Germany, Poland, the Czech Republic, Slovakia, Austria, France, Spain, the Netherlands, Estonia, Lithuania, and the United Kingdom — spanning banking apps and, in several of those countries, state eID apps. Beyond this regional focus, the monitored package list extends to global fintech and cryptocurrency services, indicating the campaign's reach and potential victim pool is not geographically confined despite its apparent primary focus on Ukraine.","heading":"Geographic Targeting and Scope","sources":[{"url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware","name":"ThreatFabric: Manic — Blend between Banking Malware & Spyware","type":"research","credibility":2},{"url":"https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/","name":"BleepingComputer: New Manic Android malware can exfiltrate data through nearby devices","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Manic is reported to spread via phishing sites and dropper/wrapper APKs that impersonate utility apps and other legitimate software, rather than through the official Google Play Store. In response to press inquiries following ThreatFabric's disclosure, a Google representative stated that, \"based on our current detection, no apps containing this malware are found on Google Play,\" and that \"Android users are automatically protected against known versions of this malware by Google Play Protect.\" This indicates the malware relies on sideloading or third-party app stores for distribution, meaning users who install apps only from Google Play and keep Play Protect enabled are considered lower-risk, according to Google's statement, though this does not eliminate risk for users who sideload apps or use alternative app marketplaces.","heading":"Distribution and Google Play Store Status","sources":[{"url":"https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/","name":"BleepingComputer: New Manic Android malware can exfiltrate data through nearby devices","type":"news_article","credibility":2},{"url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html","name":"The Hacker News: Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices","type":"news_article","credibility":2}],"severity":"medium"},{"content":"ThreatFabric's investigation traces Manic's associated infrastructure back to February 2026, with development and production services following in late March and April 2026, and the first retained malware wrapper and implant observed by late May 2026. Coverage citing ThreatFabric further describes a development hiatus from late June to mid-July 2026, followed by a reworked build in July 2026 that added stronger anti-analysis checks, in-memory DEX loading, and lock-screen secret theft. This pattern of continued, active development through mid-2026 — several months after the malware's initial appearance — indicates Manic is an actively maintained, ongoing threat rather than a one-off campaign, and further updates should be considered likely.","heading":"Development Timeline and Ongoing Evolution","sources":[{"url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware","name":"ThreatFabric: Manic — Blend between Banking Malware & Spyware","type":"research","credibility":2},{"url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html","name":"The Hacker News: Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices","type":"news_article","credibility":2}],"severity":"high"}],"timeline":[{"date":"2026-02","event":"First infrastructure associated with the Manic campaign (domain registration under a fabricated persona) is registered, marking the earliest traced activity of the malware family.","source":"ThreatFabric / BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/"},{"date":"2026-03","event":"Development and production services supporting the Manic campaign begin to come online, per ThreatFabric's infrastructure timeline (dated to late March/April 2026).","source":"ThreatFabric","source_url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"},{"date":"2026-05","event":"The first retained malware wrapper and implant appear, using a booking-app lure for initial distribution.","source":"ThreatFabric / The Hacker News","source_url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html"},{"date":"2026-07","event":"Following a development hiatus, a reworked Manic build is deployed with stronger anti-analysis protections, in-memory DEX loading, and new lock-screen secret theft capability; a new operator panel/API is also introduced.","source":"ThreatFabric / The Hacker News","source_url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html"},{"date":"2026-08-20","event":"ThreatFabric publicly discloses the Manic malware family in a technical blog post; the disclosure is simultaneously covered by The Hacker News and BleepingComputer.","source":"The Hacker News","source_url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html","date_evidence":"Aug 20, 2026 (article byline)"},{"date":"2026-08-20","event":"BleepingComputer publishes coverage of Manic's Wi-Fi/Bluetooth mesh exfiltration technique, including Google's statement that no apps containing the malware were found on Google Play.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/","date_evidence":"By Bill Toulas • August 20, 2026 • 06:02 AM"},{"date":"2026-08","event":"Kaspersky publishes its own analysis of Manic on the Kaspersky Daily blog, corroborating ThreatFabric's findings on offline data exfiltration and credential theft.","source":"Kaspersky Daily","source_url":"https://www.kaspersky.com/blog/manic-android-trojan/56323/"},{"date":"2026-08-31","event":"eSecurity Planet publishes further coverage summarizing Manic's bank-account-draining capability and offline mesh exfiltration.","source":"eSecurity Planet","source_url":"https://www.esecurityplanet.com/threats/news-manic-android-malware-device-relay-data-theft/","date_evidence":"eSecurity Planet article dated August 31, 2026"}],"sources_used":[{"url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware","name":"ThreatFabric: Manic — Blend between Banking Malware & Spyware","type":"research","archive_url":"http://web.archive.org/web/20260910023129/https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware","credibility":2,"archive_timestamp":"2026-09-10T02:31:29+00:00"},{"url":"https://www.kaspersky.com/blog/manic-android-trojan/56323/","name":"Kaspersky Daily: This Android malware steals banking credentials even without an internet connection","type":"research","archive_url":"http://web.archive.org/web/20260913142521/https://www.kaspersky.com/blog/manic-android-trojan/56323/","credibility":2,"archive_timestamp":"2026-09-13T14:25:21+00:00"},{"url":"https://www.esecurityplanet.com/threats/news-manic-android-malware-device-relay-data-theft/","name":"eSecurity Planet: New Manic Android Malware Uses Offline Networks to Drain Bank Accounts","type":"news_article","archive_url":"http://web.archive.org/web/20260918082845/https://www.esecurityplanet.com/threats/news-manic-android-malware-device-relay-data-theft/","credibility":2,"archive_timestamp":"2026-09-18T08:28:45+00:00"},{"url":"https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html","name":"Security Affairs: Manic — The Android Malware That Exfiltrates Data Even When the Phone Is Offline","type":"news_article","archive_url":"http://web.archive.org/web/20260825065626/https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html","credibility":2,"archive_timestamp":"2026-08-25T06:56:26+00:00"},{"url":"https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/","name":"BleepingComputer: New Manic Android malware can exfiltrate data through nearby devices","type":"news_article","archive_url":"http://web.archive.org/web/20260919170650/https://www.bleepingcomputer.com/news/security/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices/","credibility":2,"archive_timestamp":"2026-09-19T17:06:50+00:00"},{"url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html","name":"The Hacker News: Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices","type":"news_article","archive_url":"http://web.archive.org/web/20260917231302/https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html","credibility":2,"archive_timestamp":"2026-09-17T23:13:02+00:00"},{"url":"https://cybernews.com/news/new-android-malware/","name":"Cybernews: Android malware Manic can relay stolen data offline","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-09-19T17:08:33.91151+00:00","updated_at":"2026-09-19T20:08:42.074144+00:00"}}