Offline Android phones leak data through Manic’s Wi-Fi mesh

Manic Android malware exfiltrates data through nearby infected devices when the victim phone is offline.

CSBadmin
1 Min Read

A new Android trojan named Manic blends banking malware with spyware, and its operators built in a workaround for offline phones: infected devices relay stolen data through nearby compromised handsets over a Wi-Fi mesh, so exfiltration keeps running even with no internet on the victim’s device.

The target list spans Ukrainian banks, government and identity services, and messaging apps, plus Russian and European financial institutions, global fintech and crypto platforms, and military communications software. ThreatFabric says Manic watches 169 package IDs covering banks, payment apps, buy-now-pay-later services, and wallet tools.

Lures take the form of phishing pages and droppers posing as utility apps, sometimes branded as Lenovo or Huawei helpers, alongside packages named tech.intel.dialer.updater and org.honor.secure.helper. Activity traces back to February, when operators registered the first domain under a fabricated persona; the implant matured by late May, development stalled in late June, and a second wave around July 13 added stronger anti-analysis defenses plus lock-screen phishing, with a command panel going live in the last week of the month.

For Android users in affected regions, sticking to official app stores and treating utility apps from elsewhere with suspicion remains the practical defense.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.