Find notable cyber news and cases, enriched with sources, timelines, and signals.

Manic Android malware activity with offline relay exfiltration

Malware Activity
First reported
Last updated
Happening score
H score 29
2 unique sources, 2 articles

Summary

Hide ▲

Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial institutions plus fintech, cryptocurrency, and military-focused communications. It blends banking fraud with mobile spyware, using Android Accessibility and notification permissions for keylogging, PIN capture, screenshots, contacts/SMS theft, and remote control. ThreatFabric said the activity dates back to February 2026, with supporting wrapper and implant development through May and July 2026. Its standout capability is a Wi‑Fi Direct/Bluetooth/BLE relay that can move encrypted data through a nearby infected Android device when the victim phone cannot reach C2.

Related Happenings

StreamRat Android banking trojan with remote-control capabilities

Malware Activity
H score42 First: 02.09.2026 15:22 Last: 02.09.2026 15:22 Sources 1

About this happening: The StreamRat Android banking trojan is being pushed through fake streaming ads on Meta and can yield near-complete device control, raising the risk of credentia...

Android 17 adds OS-wide ECH, Local Network Protection, CT by default, and carrier 2G-off defaults

Security Tool/Service
H score15 First: 28.08.2026 19:20 Last: 28.08.2026 19:20 Sources 1

About this happening: Android 17 adds OS-wide network protections that reduce traffic metadata exposure and limit local-network and cellular attack surfaces. The update brings Encrypted Client He...

WhatsApp rolls out multiple passkeys, stronger two-step verification, and scam-call context

Security Tool/Service
H score11 First: 25.08.2026 16:00 Last: 25.08.2026 16:00 Sources 1

About this happening: WhatsApp is rolling out new account security controls that expand passkey support, strengthen two-step verification, and add more call-screen scam context for...

ToxicPanda 2.0 Android malware expands fraud capabilities

Malware Activity
H score29 First: 20.08.2026 13:38 Last: 20.08.2026 13:38 Sources 1

About this happening: The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...

ToxicPanda 2.0 Android banking trojan expansion

Malware Activity
H score28 First: 20.08.2026 13:00 Last: 20.08.2026 13:00 Sources 1

About this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...

Timeline

  1. 20.08.2026 13:02 3 articles · 13d ago

    Manic Android malware activity with offline relay exfiltration

    Initial Disclosure

    The Manic Android malware first surfaced as a multifunction tool aimed at banking and government/eID apps, with Ukraine as the main focus. Early activity already showed a payload-delivery wrapper and expanding supporting infrastructure.

    Show sources