Summary
- ThreatFabric says Manic monitors 169 applications spanning banking, eID, authentication, messaging and other services.
- The malware can capture credentials, surveillance data and device activity through abused Android permissions.
- A store-and-forward mechanism can relay stolen data through nearby infected devices when the original phone is offline.
A newly documented Android malware family is combining banking theft, surveillance and remote device control while concentrating much of its targeting on Ukrainian financial, government identity and communications services.
Researchers at ThreatFabric have named the malware Manic and say it monitors 169 Android application identifiers. The majority relate to Ukrainian services, although financial and other applications used in Russia, the UK and continental Europe also appear in the target list.
The applications cover banks, peer-to-peer payments, cryptocurrency services, government and electronic identity platforms, authenticators, email, browsers and commercial or military-oriented messaging. That breadth gives Manic a wider collection capability than a conventional banking trojan focused primarily on stealing account credentials.
The malware abuses Android accessibility and notification permissions to observe and manipulate activity on an infected device. ThreatFabric says it can collect passwords, one-time codes and recovery phrases, monitor notifications, take screenshots, extract contacts and messages, track location and provide an operator with remote control of the handset.
It can also place an overlay above a legitimate application and record keypad interactions while allowing the underlying app to continue functioning. That creates a route to capturing PINs without presenting the victim with an obviously separate fake banking interface.
Researchers traced infrastructure associated with Manic back to February, with the malware developing further through May and July. Distribution has been linked to phishing sites and applications impersonating legitimate utilities, while newer versions incorporate stronger anti-analysis checks and additional mechanisms for obtaining lock-screen secrets.
Its most unusual feature is a store-and-forward communication system designed to move information through other infected phones. If the original device cannot communicate directly with attacker infrastructure, Manic can search for a nearby compromised device using Wi-Fi Direct or Bluetooth technologies and pass encrypted information to it for onward transmission.
The relay system supports multiple hops and retains queued information when no suitable peer is available. Disconnecting an infected handset from the internet therefore does not necessarily prevent exfiltration if another compromised device is close enough to act as a gateway.
How frequently that mechanism succeeds outside laboratory analysis remains unclear. It nevertheless broadens the assumptions required during mobile incident response, where removing conventional network connectivity would normally be expected to cut an infected device off from its command infrastructure.
The Ukrainian focus also increases the range of potential consequences. Banking information, digital identity, authentication tokens and sensitive communications can coexist on the same personal device, particularly where mobile services have become an important route into government and financial systems.
ThreatFabric has not attributed Manic to a named criminal or state-linked operator. The surveillance functionality and inclusion of communications tools do not establish an espionage motive by themselves, particularly when the same malware also carries extensive financial-fraud capabilities.
The campaign instead shows how distinctions between banking malware, spyware and remote-access tooling are becoming less useful at device level. A single malicious implant can now collect financial credentials, observe communications, track a victim and provide direct control of the phone while using alternative communication paths to keep stolen information moving.





