A new Android malware named Manic targeting users in multiple European countries has a fallback mechanism for exfiltrating data through nearby infected devices.
The malware has been active since at least February and combines spyware, banking fraud, and remote control capabilities.
It targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA apps, with users in Ukraine being the primary focus.
Mobile security company ThreatFabric analyzed the Manic malware and found that it uses transparent overlays on the numeric keypads of legitimate applications to capture victims' taps and reproduce them through Android Accessibility, allowing the legitimate applications to continue functioning normally.
Overlays capturing user taps
Source: ThreatFabric
After obtaining Accessibility and notification access permissions, the malware can capture the lock PIN/password, intercept notifications and SMS messages, collect files and location data, monitor the screen, and provide remote control to operators via WebRTC sessions.
The captured information is categorized by type, making the data more readily exploitable for the malware operators.
“Manic uses its Accessibility service as a UI keylogger,” ThreatFabric explains, adding that the malware “classifies captured text before recording it, distinguishing lock-screen input, recovery-phrase candidates, four- to six-digit SMS codes, passwords, long messages, email logins, and ordinary text.”
Manic's attack chain
... continue reading