Manic Android malware activity with offline relay exfiltration
Malware Activity
Summary
Hide ▲
Show ▼
Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial institutions plus fintech, cryptocurrency, and military-focused communications. It blends banking fraud with mobile spyware, using Android Accessibility and notification permissions for keylogging, PIN capture, screenshots, contacts/SMS theft, and remote control. ThreatFabric said the activity dates back to February 2026, with supporting wrapper and implant development through May and July 2026. Its standout capability is a Wi‑Fi Direct/Bluetooth/BLE relay that can move encrypted data through a nearby infected Android device when the victim phone cannot reach C2.
Related Happenings
StreamRat Android banking trojan with remote-control capabilities
Malware Activity
H score42
First: 02.09.2026 15:22
Last: 02.09.2026 15:22
Sources 1
About this happening:
The StreamRat Android banking trojan is being pushed through fake streaming ads on Meta and can yield near-complete device control, raising the risk of credentia...
StreamRat Android banking trojan with remote-control capabilities
Malware ActivityAbout this happening: The StreamRat Android banking trojan is being pushed through fake streaming ads on Meta and can yield near-complete device control, raising the risk of credentia...
Android 17 adds OS-wide ECH, Local Network Protection, CT by default, and carrier 2G-off defaults
Security Tool/Service
H score15
First: 28.08.2026 19:20
Last: 28.08.2026 19:20
Sources 1
About this happening:
Android 17 adds OS-wide network protections that reduce traffic metadata exposure and limit local-network and cellular attack surfaces. The update brings Encrypted Client He...
Android 17 adds OS-wide ECH, Local Network Protection, CT by default, and carrier 2G-off defaults
Security Tool/ServiceAbout this happening: Android 17 adds OS-wide network protections that reduce traffic metadata exposure and limit local-network and cellular attack surfaces. The update brings Encrypted Client He...
WhatsApp rolls out multiple passkeys, stronger two-step verification, and scam-call context
Security Tool/Service
H score11
First: 25.08.2026 16:00
Last: 25.08.2026 16:00
Sources 1
About this happening:
WhatsApp is rolling out new account security controls that expand passkey support, strengthen two-step verification, and add more call-screen scam context for...
WhatsApp rolls out multiple passkeys, stronger two-step verification, and scam-call context
Security Tool/ServiceAbout this happening: WhatsApp is rolling out new account security controls that expand passkey support, strengthen two-step verification, and add more call-screen scam context for...
ToxicPanda 2.0 Android malware expands fraud capabilities
Malware Activity
H score29
First: 20.08.2026 13:38
Last: 20.08.2026 13:38
Sources 1
About this happening:
The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...
ToxicPanda 2.0 Android malware expands fraud capabilities
Malware ActivityAbout this happening: The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
Timeline
-
20.08.2026 13:02 3 articles · 13d ago
Manic Android malware activity with offline relay exfiltration
Initial DisclosureThe Manic Android malware first surfaced as a multifunction tool aimed at banking and government/eID apps, with Ukraine as the main focus. Early activity already showed a payload-delivery wrapper and expanding supporting infrastructure.
Show sources
- New Manic Android malware can exfiltrate data through nearby devices — www.bleepingcomputer.com — 20.08.2026 13:02
- New Manic Android malware can exfiltrate data through nearby devices — www.bleepingcomputer.com — 20.08.2026 13:02
- Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices — thehackernews.com — 20.08.2026 14:26