New Android malware called Manic steals data from offline phones using nearby infected devices. It targets banks, government services, and crypto platforms across Europe.
There's a new Android threat making the rounds, and it's unlike anything we've seen before. Security researchers have uncovered a piece of malware codenamed Manic that's actively targeting Ukrainian banks, government and identity services, and messaging apps. But here's the twist: it's also going after Russian and European financial institutions, global fintech and cryptocurrency services, and even military-focused communications.
What makes Manic so dangerous isn't just what it steals—it's how it works. This malware sits at the intersection of Android banking malware and mobile spyware, combining financial fraud with stealthy surveillance. And the most unsettling part? It can exfiltrate data from phones that are completely offline, using nearby infected devices as a relay.
### How Does Manic Actually Work?
Think of it like a game of telephone, but with your sensitive data. When Manic infects a device, it doesn't just wait for you to open a banking app. It actively scans for other vulnerable phones in the vicinity using Bluetooth and Wi-Fi connections. If it finds one, it can piggyback on that connection to pull data from the offline device.
Here's the breakdown of what Manic targets:
- Banking credentials and financial account details
- Government and identity service logins
- Messaging app conversations and contacts
- Cryptocurrency wallet information
- Military communications data
This isn't a simple phishing scam. Manic is a sophisticated piece of spyware that can operate silently in the background, capturing keystrokes, taking screenshots, and recording audio without the user ever knowing something is wrong.
### Why Offline Phones Aren't Safe Anymore
Most people assume that if their phone is in airplane mode or has no cellular connection, they're safe from malware. That's a reasonable assumption—until now. Manic exploits the proximity features that modern smartphones use for file sharing and device-to-device communication.
Imagine you're in a secure facility and you've deliberately turned off your phone's data connection to prevent any leaks. An infected phone walks past you in the hallway. Within seconds, Manic can establish a connection and start pulling your data through that other device's internet connection.
This technique, sometimes called a "proximity relay attack," is particularly concerning for government employees, military personnel, and financial professionals who handle sensitive information.
### Who's Behind the Attacks?
Researchers haven't confirmed who's responsible for Manic, but the targeting pattern tells a story. The malware is actively hitting Ukrainian institutions while also going after Russian financial targets. This suggests either a hacktivist group, a state-sponsored operation, or a cybercrime syndicate with geopolitical motivations.
The dual targeting of both Ukrainian and Russian entities is unusual. Most malware campaigns focus on one side or the other. Manic's broad reach across Europe, combined with its focus on fintech and crypto, suggests the attackers are casting a wide net to maximize their financial gains.
### What Should You Do to Protect Your Devices?
While the threat sounds scary, there are practical steps you can take to reduce your risk:
- Keep your Android operating system updated with the latest security patches
- Avoid sideloading apps from unofficial sources
- Review app permissions regularly and revoke access to anything suspicious
- Turn off Bluetooth and Wi-Fi when you don't need them
- Use a reputable mobile security app that can detect unusual behavior
For organizations handling sensitive data, it's worth implementing stricter mobile device management policies. That might include disabling peer-to-peer file sharing features, enforcing VPN usage, and requiring regular security audits.
### The Bottom Line
Manic represents a new evolution in mobile malware. It's no longer enough to just be careful about what you download or which links you click. The threat landscape has expanded to include proximity-based attacks that can compromise even air-gapped devices.
If you're in the banking, government, or military sectors, this is the time to review your mobile security protocols. And if you're just an everyday user, stay vigilant about what you install and which permissions you grant.
Stay safe out there. The digital world just got a little more complicated.