Security researchers have uncovered a sophisticated new Android malware strain called Manic that blends financial fraud and full-device espionage. Instead of relying only on the usual overlay attacks, Manic quietly records PIN inputs, hijacks banking app sessions, captures messages and location, and can even monitor screens live. Its toolkit is among the most versatile yet seen in Android threats.([cybersecuritynews.com](https://cybersecuritynews.com/manic-android-malware/))
What Makes Manic Different
Manic doesn’t follow the typical path of faking login screens over legitimate apps. It gains Accessibility and notification permissions to place a transparent layer atop the numeric keypad within genuine banking apps, capturing PIN entries without disturbing the user. Then it replays those inputs using Accessibility services so the transactions appear legit, all while logging data in the background.([cybersecuritynews.com](https://cybersecuritynews.com/manic-android-malware/)) Likewise, it targets the device’s lock screen to grab unlock codes or patterns, intercepts SMS or notifications and can conduct live screen-sharing through WebRTC for remote control.([cybersecuritynews.com](https://cybersecuritynews.com/manic-android-malware/))
Regional and Functional Scope
Manic has been active since at least February 2026, with its development ramping up into mid-year. A more advanced build with stronger anti-analysis defenses and in-memory code execution appeared by July.([cybersecuritynews.com](https://cybersecuritynews.com/manic-android-malware/)) It monitors 169 different apps, including banks, identity portals, payment services, crypto wallets and exchanges, authenticator tools, and messaging platforms.([cybersecuritynews.com](https://cybersecuritynews.com/manic-android-malware/)) While Ukraine is the primary target—particularly national banks and identity systems—the malware is not confined there. It also affects users in Russia, Poland, Germany, Czechia, Slovakia, the UK, and various global fintech/crypto services.([cybersecuritynews.com](https://cybersecuritynews.com/manic-android-malware/))
Peer-to-Peer Data Exfiltration
Perhaps its most unusual trait: Manic creates a mesh-like relay network among infected phones. When an infected device lacks internet access, it encrypts stolen data and scans for another nearby compromised device with connectivity via Wi-Fi Direct, Bluetooth, or BLE. That peer device then forwards the data to the command-and-control server.([cybersecuritynews.com](https://cybersecuritynews.com/manic-android-malware/)) This technique lets the malware bypass rudimentary network-level blocks—cutting off one phone’s connectivity doesn’t stop the data flow if there’s another infected device in range.([cybersecuritynews.com](https://cybersecuritynews.com/manic-android-malware/))
Mitigation and Defense Advice
Experts recommend users strictly avoid installing APKs from untrusted outside sources. Also, any app asking for Accessibility permissions should be scrutinized. Keeping Google Play Protect active is advised, as Manic depends heavily on Accessibility rights to carry out its attacks.([cybersecuritynews.com](https://cybersecuritynews.com/manic-android-malware/))
This malware represents a worrying evolution: combining transparent PIN theft, deep surveillance, and multi-device relaying into one unified platform. As more drift away from single-method attacks, Manic shows what Android threats are becoming: harder to detect, more resilient, and capable of adapting to restrictive environments. Watch for defenders to prioritize behavioral detection over permission audits, and for updates from device vendors to clamp down on cross-device relays. What we have here isn’t just another trojan—it’s a new benchmark for risk.