Skip to content
Tech News
← Back to articles

New Manic Android malware can exfiltrate data through nearby devices

read original more articles
Why This Matters

The emergence of Manic Android malware highlights evolving threats in mobile security, especially with its innovative data exfiltration method through nearby infected devices. This development underscores the need for enhanced security measures for consumers and the industry to combat sophisticated malware that can bypass traditional defenses and leverage proximity-based data transfer. Staying vigilant against such threats is crucial to protect sensitive personal and financial information in an increasingly interconnected digital landscape.

Key Takeaways

A new Android malware named Manic targeting users in multiple European countries has a fallback mechanism for exfiltrating data through nearby infected devices.

The malware has been active since at least February and combines spyware, banking fraud, and remote control capabilities.

It targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA apps, with users in Ukraine being the primary focus.

Mobile security company ThreatFabric analyzed the Manic malware and found that it uses transparent overlays on the numeric keypads of legitimate applications to capture victims' taps and reproduce them through Android Accessibility, allowing the legitimate applications to continue functioning normally.

Overlays capturing user taps

Source: ThreatFabric

After obtaining Accessibility and notification access permissions, the malware can capture the lock PIN/password, intercept notifications and SMS messages, collect files and location data, monitor the screen, and provide remote control to operators via WebRTC sessions.

The captured information is categorized by type, making the data more readily exploitable for the malware operators.

“Manic uses its Accessibility service as a UI keylogger,” ThreatFabric explains, adding that the malware “classifies captured text before recording it, distinguishing lock-screen input, recovery-phrase candidates, four- to six-digit SMS codes, passwords, long messages, email logins, and ordinary text.”

Manic's attack chain

... continue reading