A New Android Malware Threats European Users with Unusual Data Exfiltration Mechanism
A sophisticated Android malware, dubbed Manic, has been targeting users in multiple European countries since at least February. What makes this threat particularly concerning is its fallback mechanism for exfiltrating data through nearby infected devices, allowing attackers to bypass traditional command-and-control (C2) server connections.
According to an analysis by mobile security company ThreatFabric, Manic combines spyware, banking fraud, and remote control capabilities, targeting at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA apps. The primary focus appears to be on users in Ukraine, as well as global fintech and cryptocurrency services.
To understand how this malware operates, it’s essential to grasp its core feature: transparent overlays on legitimate application keypads that capture victims’ taps and reproduce them through Android Accessibility. This allows the malware to capture sensitive information without disrupting normal app functionality. Once installed, Manic can obtain Accessibility and notification access permissions, enabling it to intercept notifications, SMS messages, collect files and location data, monitor the screen, and provide remote control to operators via WebRTC sessions.
The most striking aspect of this threat is its ability to exfiltrate data through nearby infected devices when a compromised device cannot reach the C2 server. This is achieved by encrypting and transferring data over Wi-Fi Direct or Bluetooth connections, essentially creating a network of compromised devices that can facilitate data transfer even from offline devices. ThreatFabric notes that Manic first attempts to use an established Wi-Fi Direct peer, then queries Bluetooth and BLE peers to determine whether they have internet connectivity.
The scope of this threat is significant, with targets spanning Central and Western Europe, including the UK, as well as Russia. Android users are advised to exercise caution when downloading APKs from unknown sources and to deny Accessibility permissions unless required by a trusted application. Regularly running Play Protect scans can also help detect and remove known malware.
The emergence of Manic underscores the evolving nature of mobile threats, where attackers increasingly employ sophisticated techniques to evade detection and maximize data exfiltration capabilities. As users become more reliant on their devices for sensitive transactions and information exchange, it’s essential to remain vigilant about software updates, permissions, and device security settings.
To protect yourself from this threat, avoid downloading APKs from obscure sources and unofficial portals, be cautious when granting Accessibility permissions, and regularly run Play Protect scans. By staying informed and taking proactive measures, we can mitigate the impact of these sophisticated threats and maintain a secure digital landscape.
Source: Bleeping Computer — 2026-08-20