HackMyIP
← Back to News
2026-08-20 The Hacker News

Manic Android Malware Exfiltrates Data via Wi-Fi Mesh from Offline Devices

MalwarePhishingThreat Intel

A new Android malware strain dubbed Manic has been uncovered by ThreatFabric, blending banking fraud capabilities with mobile spyware features to target Ukrainian banks, government and identity services, military-focused messaging applications, as well as Russian and European financial institutions, global fintech platforms, and cryptocurrency services. Active since February 2026, the malware is distributed through phishing sites and dropper apps impersonating legitimate utilities such as booking applications, with APK packages including tech.intel.dialer.updater and org.lenovo.storage.processor deployed as wrappers and implants respectively. The campaign's evolution shows a brief lull from late June to mid-July before a hardened second iteration emerged on July 13, featuring stronger anti-analysis checks and the ability to phish lock screen secrets, with the corresponding command panel and API going live between July 24 and 28.

The most notable technical innovation is Manic's Wi-Fi mesh exfiltration technique, which allows infected devices without direct internet connectivity to relay stolen data through nearby compromised devices that do have network access. This approach effectively bypasses isolation strategies for offline or air-gapped handsets and significantly extends the malware's reach in environments where sensitive devices are intentionally kept off public networks. The threat achieves its surveillance goals by abusing Android's accessibility services and notification permissions, enabling real-time location tracking, notification interception, file collection, and remote device control. Operators monitor an extensive list of 169 package IDs spanning banking apps, peer-to-peer payment services, Buy Now Pay Later platforms, cryptocurrency wallets and exchanges, messaging applications, government eID services, browsers, authenticators, and email clients—predominantly Ukrainian but also covering Russia, Central and Western Europe, and the U.K.

To defend against Manic and similar spyware families, users should avoid sideloading APK files from outside the Google Play Store, scrutinize accessibility service permissions on every installed app, and keep device firmware current. Security teams should monitor local network traffic for unusual peer-to-peer patterns indicative of mesh-based relay behavior, and individuals concerned about credential exposure can verify their accounts using an email breach checker while running a DNS leak test to confirm no covert routing is occurring through a compromised local endpoint. A broader privacy checkup is also recommended to audit device telemetry and surface any background data flows that may indicate compromise.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →