Manic Android malware hops between infected phones to steal Ukrainian banking data
Researchers at ThreatFabric say the spyware, active since February, targets 169 apps and can relay stolen data through nearby infected devices over Wi-Fi Direct or Bluetooth when the internet is unavailable.

Key points
- ThreatFabric has been tracking a new Android spyware family called Manic since at least February 2024, with Ukrainian users the primary target.
- The malware targets 169 apps across banking, government identity, payments, cryptocurrency wallets, messaging and two-factor authentication.
- Manic can relay stolen data through nearby infected phones over Wi-Fi Direct or Bluetooth when it can't reach its operators directly, using up to four hops.
- An updated version seen in July added stronger anti-analysis checks and loads its code straight into memory to avoid detection.
- The initial infection route isn't yet confirmed, but a delivery wrapper was seen in late May and refreshed over the summer.
A new piece of Android spyware is being used against people in Ukraine and across parts of Europe. Mobile security firm ThreatFabric calls it Manic. When it can't phone home to its operators, it looks for other infected phones nearby and passes stolen data through them instead.
What can Manic actually do?
Once installed, Manic tricks the user into granting Android's Accessibility permission, a powerful setting meant to help people with disabilities but routinely abused by malware to read and control the screen.
From there it can capture the phone's lock PIN or password, intercept SMS messages and notifications, collect files and location data, and hand live remote control to the operator through WebRTC, a video-and-data channel built into most mobile browsers.
It also lays transparent overlays on top of the number pads inside real banking apps. The victim taps their PIN; Manic records it, then replays it into the genuine app so nothing looks wrong.
As text is captured it's sorted immediately. ThreatFabric says the malware "classifies captured text before recording it, distinguishing lock-screen input, recovery-phrase candidates, four- to six-digit SMS codes, passwords, long messages and email logins", which makes the loot immediately useful to whoever is running the campaign.
Who is being targeted?
Ukrainian banking and government electronic-ID apps are the clear priority. ThreatFabric also lists targets in the United Kingdom, Central Europe and Russia, plus global cryptocurrency and fintech services. In total, 169 apps are on the hit list.
Attribution is thin. ThreatFabric hasn't tied Manic to a named cluster, and the Ukraine focus plus interest in eID apps is consistent with financially motivated crews or espionage-adjacent activity. I wouldn't read intent from the target list alone, especially on a single vendor's telemetry. Our earlier piece on SpyNote and WindRelay showed how quickly banking-fraud tooling can be repurposed once the infrastructure exists.
How does the phone-to-phone relay work?
If a compromised device loses its connection to the command-and-control server (the remote machine the malware takes orders from), Manic doesn't just wait.
It checks first for an existing Wi-Fi Direct link to another infected phone, then scans over Bluetooth and Bluetooth Low Energy for peers that do have internet. Data is encrypted and pushed through that peer instead.
"If necessary, the malware can also use multi-hop routes, with newly queued items configured for a maximum of four relay hops by default," ThreatFabric writes. An offline phone in a café can still leak its owner's banking PIN as long as one other infected device is within range. That's not a theoretical edge case; it's a deliberate architectural choice.
| Detail | What ThreatFabric found |
|---|---|
| First seen | February 2024 |
| Apps targeted | 169 |
| Primary victims | Ukraine (banking, eID) |
| Relay range | Wi-Fi Direct, Bluetooth, BLE |
| Max relay hops | 4 |
| July update | Anti-analysis checks, in-memory DEX loading |
Should you worry?
If you're an Android user in Ukraine or anywhere the target list overlaps, yes, practically. Avoid installing APK files from websites or message links. When any app asks for Accessibility permission, stop: a banking app doesn't need it, and neither does anything else in ordinary use. Run a Play Protect scan from the Play Store's profile menu periodically. It isn't perfect, but it catches known families once samples are flagged.



