Skip to finding
important · Mobile

Manic can exfiltrate data from an offline infected Android phone through nearby infected phones.

Affects

Manic, an Android banking-malware and spyware family targeting financial, identity, government, messaging, and authentication applications.

The source phone must already run the implant with Accessibility and notification access, and a nearby infected handset must provide a route. Manic moves AES-GCM-encrypted queues over Wi-Fi Direct, Bluetooth RFCOMM or BLE through as many as four infected peers until one reaches the command server.

Detail and 2 sources

ThreatFabric identified the malware as actively distributed. The new capability defeats direct-network isolation of an already infected phone; it does not remove the initial compromise requirement.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 24, 2026