2 Remove Virus

Manic Android malware can relay stolen data through nearby infected phones

Security researchers have uncovered an Android malware strain that combines banking fraud, surveillance, and remote device control with an unusual method for moving stolen information between infected smartphones.

 

 

Named Manic by researchers at ThreatFabric, the malware targets 169 applications spanning banking, payment services, cryptocurrency platforms and wallets, messaging services, government applications, authenticators, browsers, and email clients. Its primary focus is Ukraine, although its target list also covers Russian and European financial institutions, international fintech and cryptocurrency services, and military-oriented communications.

Once Manic obtains Accessibility Service and notification permissions, its operators can gain extensive access to the compromised Android device. The malware can collect passwords, one-time authentication codes, and cryptocurrency recovery phrases while also monitoring text messages.

Manic can abuse overlays and deceptive screens when victims use targeted banking or cryptocurrency applications. These techniques allow it to conceal malicious activity and capture information entered through on-screen keypads. Abuse of Android Accessibility Services additionally enables attackers to observe what is displayed on the screen and remotely interact with the device.

ThreatFabric found that Manic can capture information associated with methods used to unlock a phone, including PINs, passwords, patterns, fingerprints, and facial recognition. Researchers characterize the malware as combining functionality associated with Android banking threats with broader spyware capabilities.

One of Manic’s more distinctive capabilities concerns how it exfiltrates information. Stolen files and data are encrypted using AES-GCM and stored in a local queue while the malware searches for a path to its command-and-control infrastructure.

A compromised phone does not necessarily need its own internet connection to deliver that information. Manic can transfer queued data to another infected Android device located nearby using Wi-Fi Direct or Bluetooth. That second device can then act as a relay and forward the stolen information toward infrastructure controlled by the attackers.

If neither a direct connection nor another suitable infected device is available, Manic keeps the encrypted data queued and attempts transmission again later.

This capability means disconnecting an infected smartphone from the internet alone may not be sufficient to stop information from leaving the device. If another Manic-infected phone is within wireless range, the malware may still have an alternative route for transmitting stolen information.

Researchers have not identified Manic on the Google Play Store. The malware therefore reinforces the risks associated with installing Android APK files obtained through untrusted websites or other unofficial distribution sources.