Manic Android malware hops between infected phones to steal Ukrainian banking data
Researchers at ThreatFabric say the spyware, active since February, targets 169 apps and can relay stolen data through nearby infected devices over Wi-Fi Direct or Bluetooth when the internet is unavailable.

Key points
- ThreatFabric has been tracking a new Android spyware family called Manic since at least February 2024, with Ukrainian users the primary target.
- The malware targets 169 apps across banking, government identity, payments, cryptocurrency wallets, messaging and two-factor authentication.
- Manic can relay stolen data through nearby infected phones over Wi-Fi Direct or Bluetooth when it cannot reach its operators directly, using up to four hops.
- An updated version seen in July added stronger anti-analysis checks and loads its code straight into memory to avoid detection.
- The initial infection route is not yet confirmed, but a delivery wrapper was seen in late May and refreshed over the summer.
A new piece of Android spyware, malicious software that quietly watches and steals from a phone, is being used against people in Ukraine and across parts of Europe. Mobile security firm ThreatFabric calls it Manic, and first reporting on the family came via BleepingComputer.
The unusual bit: when Manic cannot phone home to its operators, it looks for other infected phones nearby and passes the stolen data through them instead.
What can Manic actually do?
A lot. Once installed, Manic tricks the user into granting Android's Accessibility permission, a powerful setting meant to help people with disabilities but often abused by malware to read and control the screen.
From there it can capture the phone's lock PIN or password, read incoming text messages and notifications, grab files, track location, and hand live remote control to the operator through a video-and-data channel called WebRTC.
It also lays transparent overlays on top of the number pads inside real banking apps. The victim taps their PIN, Manic records the taps, then replays them into the genuine app so nothing looks wrong.
The stolen text is sorted as it is captured. ThreatFabric says the malware separates "lock-screen input, recovery-phrase candidates, four- to six-digit SMS codes, passwords, long messages, email logins, and ordinary text," which makes the loot immediately useful to whoever is running the campaign.
Who is being targeted?
Ukrainian banking and government electronic-ID apps are the clear priority, alongside global cryptocurrency and fintech services. ThreatFabric also lists targets in the United Kingdom, Central and Western Europe, and Russia. In total, 169 apps are on the hit list.
Attribution is thin. ThreatFabric has not tied Manic to a named cluster, and the Ukraine focus plus interest in eID apps is consistent with either financially motivated crews or espionage-adjacent activity. I would not read intent from target list alone, especially on a single vendor's telemetry.
How does the phone-to-phone relay work?
If a compromised device loses its connection to the command-and-control server (the machine on the internet the malware takes orders from), Manic does not just give up and wait.
It first checks for an existing Wi-Fi Direct link to another infected phone, then scans over Bluetooth and Bluetooth Low Energy for peers that do have internet. Data is encrypted and pushed through that peer instead.
"If necessary, the malware can also use multi-hop routes, with newly queued items configured for a maximum of four relay hops by default," ThreatFabric writes. In plain terms: an offline phone in a cafe can still leak its owner's banking PIN, as long as another infected phone is in Wi-Fi or Bluetooth range.
| Detail | What ThreatFabric found |
|---|---|
| First seen | February 2024 |
| Apps targeted | 169 |
| Primary victims | Ukraine (banking, eID) |
| Relay range | Wi-Fi Direct, Bluetooth, BLE |
| Max relay hops | 4 |
| July update | Anti-analysis checks, in-memory DEX loading |
What should ordinary Android users do?
Do not install Android app files (APKs) from random websites, message links or unofficial stores. Stick to Google Play.
When an app asks for Accessibility permission, stop and think. A calculator or a wallpaper app has no business with it. Banking apps do not need it either.
Run a Play Protect scan from the Play Store's profile menu now and then. It is not perfect, but it catches known families like this one once samples are flagged.



