Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
Cluster
mainnet-beta
Slot
448470725
Off-chain at
2026-09-19T17:08:51.338Z
Anchored at
Block time

Independent verification

1. Database (off-chain)
DncA7Q5eapjySPJdDgCW9tA5y4eH7C4qbRLwMiZLcHni
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (18123 chars)
{"actor":"system:backfill","investigation_id":"039f4f91-abad-47bb-896d-1d08485ebfc5","kind":"publish","page_slug":"manic-android-banking-trojan","published_at":"2026-09-19T17:08:51.215Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Manic Android Banking Trojan","sections":[{"content":"Manic is an Android hybrid threat described by ThreatFabric as sitting 'at the intersection of Android banking malware and mobile spyware, combining financial-fraud capabilities with broader surveillance and device-control features.' It was publicly disclosed by ThreatFabric in August 2026, with Kaspersky providing a parallel analysis. The malware is actively developed, with at least two deployment phases identified: an initial release in late May 2026 and an updated version deployed around July 13, 2026 that introduced in-memory DEX loading and stronger anti-analysis protections. It is not distributed via the Google Play Store; instead it spreads through phishing sites, unofficial app stores, pirate websites, dropper applications impersonating device utilities, and messaging apps.","heading":"Threat Overview","severity":"critical","sources":[{"credibility":1,"name":"ThreatFabric: Manic - Blend between Banking Malware and Spyware","type":"research","url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"},{"credibility":1,"name":"Kaspersky: This Android malware steals banking credentials even without an internet connection","type":"research","url":"https://www.kaspersky.com/blog/manic-android-trojan/56323/"}]},{"content":"Manic monitors 169 Android application package IDs, a scope that explicitly encompasses cryptocurrency exchanges and wallets alongside banks, payment services, government eID applications, two-factor authenticator apps, messaging apps, browsers, and email clients. ThreatFabric's analysis confirms the malware targets global fintech and cryptocurrency services in addition to its primary Ukrainian bank and government targets. The malware's credential-capture and device-takeover capabilities are fully applicable to crypto wallet applications: it can record seed phrases and recovery strings, capture PINs and passwords, intercept one-time codes from authenticator apps and SMS messages, and allow operators to remotely interact with device screens in real time via WebRTC sessions, enabling direct manipulation of wallet and exchange interfaces on compromised devices.","heading":"Cryptocurrency and Wallet Targeting","severity":"critical","sources":[{"credibility":1,"name":"ThreatFabric: Manic - Blend between Banking Malware and Spyware","type":"research","url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"},{"credibility":2,"name":"The Hacker News: Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices","type":"news_article","url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html"},{"credibility":2,"name":"SecurityWeek: Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight","type":"news_article","url":"https://www.securityweek.com/banking-trojans-manic-grandoreiro-toxicpanda-2-0-in-the-spotlight/"}]},{"content":"Manic employs multiple complementary credential-theft methods. Its primary technique, described by Kaspersky as 'UI keylogging,' generates a transparent capture layer over the device keyboard that records all keystrokes and then replays them into the legitimate underlying app via Android Accessibility Services, bypassing anti-fraud measures that would detect fake overlay login screens. A separate mechanism places an invisible overlay specifically over numeric keypads to intercept PIN entry while passing taps through to the real app, so the user sees no anomaly. The malware automatically classifies captured text before recording it, distinguishing lock-screen input, recovery-phrase candidates, four- to six-digit SMS codes, passwords, long-form messages, email logins, and ordinary text. It also intercepts SMS messages and app notifications in real time to capture one-time verification codes before the user can act on them. In its July 2026 update, lock-screen secret phishing was added, enabling capture of device unlock patterns and PINs directly.","heading":"Technical Capabilities: Credential Theft","severity":"critical","sources":[{"credibility":1,"name":"Kaspersky: This Android malware steals banking credentials even without an internet connection","type":"research","url":"https://www.kaspersky.com/blog/manic-android-trojan/56323/"},{"credibility":1,"name":"ThreatFabric: Manic - Blend between Banking Malware and Spyware","type":"research","url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"},{"credibility":2,"name":"The Hacker News: Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices","type":"news_article","url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html"}]},{"content":"Beyond credential theft, Manic provides operators with full Device Takeover (DTO) capability through WebRTC-based remote screen monitoring and interaction. Operators can view the device screen in real time and inject input, enabling them to conduct fraudulent transactions directly within banking and wallet applications while the device owner is unaware. Additional surveillance functions include real-time GPS location tracking, screenshot capture, file exfiltration, harvesting of contacts and call history, and the ability to send SMS messages to attacker-supplied numbers. The malware attempts to disable Google Play Protect to evade detection, and hides its presence by removing itself from the device's app launcher and using black screens and fake system update messages to conceal operator activity during remote sessions.","heading":"Technical Capabilities: Device Takeover and Surveillance","severity":"critical","sources":[{"credibility":1,"name":"ThreatFabric: Manic - Blend between Banking Malware and Spyware","type":"research","url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"},{"credibility":2,"name":"Security Affairs: Manic - The Android Malware That Exfiltrates Data Even When the Phone Is Offline","type":"news_article","url":"https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html"}]},{"content":"Manic introduces a technique not previously documented in Android banking malware: a store-and-forward proximity relay that allows stolen data to be exfiltrated from a device that has no direct internet connection. When the primary infected device is offline, it stores collected data locally and scans for nearby devices also infected with Manic via Wi-Fi Direct, Bluetooth RFCOMM, or Bluetooth Low Energy (BLE) GATT protocols. The data is then relayed peer-to-peer through a chain of up to four infected devices, each acting as a hop until a device with active internet connectivity forwards the payload to the command-and-control server. ThreatFabric describes this as a 'store-and-forward relay mechanism.' This design defeats network-level detection strategies that rely on monitoring outbound connections from a single compromised device, and significantly raises the operational resilience of the malware's C2 communications.","heading":"Novel Offline Exfiltration: Wi-Fi Mesh Relay","severity":"critical","sources":[{"credibility":1,"name":"ThreatFabric: Manic - Blend between Banking Malware and Spyware","type":"research","url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"},{"credibility":1,"name":"Kaspersky: This Android malware steals banking credentials even without an internet connection","type":"research","url":"https://www.kaspersky.com/blog/manic-android-trojan/56323/"},{"credibility":2,"name":"Security Affairs: Manic - The Android Malware That Exfiltrates Data Even When the Phone Is Offline","type":"news_article","url":"https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html"}]},{"content":"According to ThreatFabric's analysis, Manic's primary targeting is concentrated on Ukraine, covering Ukrainian banking institutions, government and electronic identity services, and military-focused messaging applications. Secondary targeting extends to Russia, and to European countries including Poland, Czech Republic, Slovakia, Austria, Germany, France, Spain, the Netherlands, Estonia, Lithuania, and the United Kingdom. The 169-package target list also includes global fintech and cryptocurrency services without geographic restriction, meaning crypto wallet and exchange users outside of Europe are also within scope. Cybernews described the malware as targeting 'government institutions, banking applications and cryptocurrency wallets' across this range.","heading":"Geographic Targeting and Scope","severity":"high","sources":[{"credibility":1,"name":"ThreatFabric: Manic - Blend between Banking Malware and Spyware","type":"research","url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"},{"credibility":2,"name":"Cybernews: New Android malware blurs the line between banking trojan and spyware","type":"news_article","url":"https://cybernews.com/news/new-android-malware/"}]},{"content":"Manic is not available through the Google Play Store. According to ThreatFabric and Kaspersky, it is distributed through phishing sites, unofficial app stores, pirate software websites, and messaging apps. Dropper applications have been observed impersonating legitimate device utilities. ThreatFabric identified the following package names used in dropper variants: tech.intel.dialer.updater, org.honor.secure.helper, org.lenovo.storage.processor, and dev.huawei.media.helper. The initial wrapper in late May 2026 used a booking application as a lure. Infrastructure was first registered in February 2026, with production C2 services active by late March to April 2026. C2 infrastructure was confirmed live between July 24 and 28, 2026.","heading":"Distribution and Indicators of Compromise","severity":"high","sources":[{"credibility":2,"name":"The Hacker News: Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices","type":"news_article","url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html"},{"credibility":1,"name":"ThreatFabric: Manic - Blend between Banking Malware and Spyware","type":"research","url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"}]},{"content":"The July 2026 update to Manic introduced a set of anti-analysis and evasion improvements documented by ThreatFabric. These include in-memory DEX loading, which executes malicious code directly in memory without writing decrypted payloads to disk, making static analysis and forensic recovery significantly harder. The update also added stronger anti-analysis checks. The malware removes itself from the Android app launcher to prevent casual discovery. During operator-controlled remote sessions, it deploys a black-screen overlay and fake system-update messages to prevent the device owner from observing or interrupting fraudulent activity. Google Play Protect disabling is attempted at runtime.","heading":"Anti-Analysis and Evasion Techniques","severity":"high","sources":[{"credibility":1,"name":"ThreatFabric: Manic - Blend between Banking Malware and Spyware","type":"research","url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"},{"credibility":2,"name":"Security Affairs: Manic - The Android Malware That Exfiltrates Data Even When the Phone Is Offline","type":"news_article","url":"https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html"}]},{"content":"Manic is malware; it is a threat actor tool, not a financial platform or entity that controls user funds. Android device users are the victims. Individuals at elevated risk are those who use Android devices to access cryptocurrency wallets or exchanges, banking applications, or two-factor authenticator apps, particularly in Ukraine and Europe but also globally for crypto and fintech platforms. The malware's victims are users whose credentials, funds, or personal data may be stolen through infection; the malware's operators are the party conducting the fraud. No law enforcement arrests, indictments, or regulatory actions related to Manic had been publicly reported as of the date of this investigation.","heading":"Affected Parties and Victim Profile","severity":"medium","sources":[{"credibility":1,"name":"Kaspersky: This Android malware steals banking credentials even without an internet connection","type":"research","url":"https://www.kaspersky.com/blog/manic-android-trojan/56323/"},{"credibility":1,"name":"ThreatFabric: Manic - Blend between Banking Malware and Spyware","type":"research","url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"}]},{"content":"As of September 2026, Manic is an active and ongoing threat. No takedown, arrest, or significant disruption of its infrastructure has been publicly reported. The malware was still under active development as of the July 2026 update, per ThreatFabric. Users can reduce exposure by installing applications only from the official Google Play Store, scrutinizing Accessibility Service permission requests from any application, keeping Android security patches current, and using a reputable mobile security solution. Crypto holders specifically should use hardware wallets that do not expose seed phrases to Android apps, enable withdrawal allowlisting on exchanges, and treat any unexpected authentication prompts on a device with suspicion.","heading":"Current Status and Mitigation","severity":"high","sources":[{"credibility":1,"name":"Kaspersky: This Android malware steals banking credentials even without an internet connection","type":"research","url":"https://www.kaspersky.com/blog/manic-android-trojan/56323/"},{"credibility":1,"name":"ThreatFabric: Manic - Blend between Banking Malware and Spyware","type":"research","url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"}]}],"sources_used":[{"credibility":1,"name":"ThreatFabric: Manic - Blend between Banking Malware and Spyware","type":"research","url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"},{"credibility":1,"name":"Kaspersky: This Android malware steals banking credentials even without an internet connection","type":"research","url":"https://www.kaspersky.com/blog/manic-android-trojan/56323/"},{"credibility":2,"name":"The Hacker News: Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices","type":"news_article","url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html"},{"credibility":2,"name":"Security Affairs: Manic - The Android Malware That Exfiltrates Data Even When the Phone Is Offline","type":"news_article","url":"https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html"},{"credibility":2,"name":"SecurityWeek: Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight","type":"news_article","url":"https://www.securityweek.com/banking-trojans-manic-grandoreiro-toxicpanda-2-0-in-the-spotlight/"},{"credibility":2,"name":"Cybernews: New Android malware blurs the line between banking trojan and spyware","type":"news_article","url":"https://cybernews.com/news/new-android-malware/"}],"summary":"Manic is an active Android malware family first identified by ThreatFabric and Kaspersky in 2026, combining banking-trojan credential theft, spyware, and remote device takeover. It targets 169 Android application package IDs including cryptocurrency wallets, exchanges, banks, authenticators, and government eID services, and employs a novel offline Wi-Fi mesh relay to exfiltrate stolen data through chains of nearby infected devices even without direct internet access. Primary targeting is concentrated on Ukraine, with secondary reach across Russia, Europe, and global fintech and cryptocurrency platforms.","timeline":[{"date":"2026-02-01","event":"First Manic-associated infrastructure domains registered, per ThreatFabric analysis.","source":"ThreatFabric","source_url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"},{"date":"2026-03-01","event":"Manic production C2 services come online in late March to April 2026.","source":"ThreatFabric","source_url":"https://www.threatfabric.com/blogs/manic-blend-between-banking-malware-and-spyware"},{"date":"2026-05-01","event":"First retained Manic wrapper and implant samples appear in late May 2026, using a booking-app lure.","source":"ThreatFabric / The Hacker News","source_url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html"},{"date":"2026-07-13","event":"Updated Manic wrapper deployed with in-memory DEX loading, enhanced anti-analysis protections, lock-screen secret phishing, and launcher-hiding behavior.","source":"ThreatFabric / The Hacker News","source_url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html"},{"date":"2026-07-24","event":"Manic C2 infrastructure confirmed live, with panel and API active through approximately July 28, 2026.","source":"ThreatFabric / The Hacker News","source_url":"https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html"},{"date":"2026-08-22","event":"ThreatFabric publishes full technical disclosure of Manic. Kaspersky publishes parallel analysis. SecurityWeek, The Hacker News, Security Affairs, and other outlets report on the disclosure.","source":"ThreatFabric / SecurityWeek","source_url":"https://www.securityweek.com/banking-trojans-manic-grandoreiro-toxicpanda-2-0-in-the-spotlight/"}]},"v":1}