Manic can exfiltrate data from an offline infected Android phone through nearby infected phones.
Manic, an Android banking-malware and spyware family targeting financial, identity, government, messaging, and authentication applications.
The source phone must already run the implant with Accessibility and notification access, and a nearby infected handset must provide a route. Manic moves AES-GCM-encrypted queues over Wi-Fi Direct, Bluetooth RFCOMM or BLE through as many as four infected peers until one reaches the command server.
Detail and 2 sources
ThreatFabric identified the malware as actively distributed. The new capability defeats direct-network isolation of an already infected phone; it does not remove the initial compromise requirement.