Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Manic Android Malware Targets 169 Apps Across Europe, Researchers Warn

Manic Android Malware Targets 169 Apps Across Europe, Researchers Warn

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 20, 2026

Human Written
Manic Android Malware Targets 169 Apps Across Europe, Researchers Warn
  • Manic Android malware targets 169 financial, messaging, and government apps across Europe using transparent overlays that capture screen taps.

  • The malware has an offline mesh mechanism for forwarding encrypted stolen data through surrounding infected devices using either Wi-Fi Direct or Bluetooth technology.

  • Security experts advise to refrain from downloading applications from external sources, to limit Accessibility permissions, and to perform regular security checks on devices.

A new high-tech Android malware variant called Manic is threatening mobile users across several European countries. The malicious software operates using some pathways, employs spyware monitoring, financial scams, and remote control capabilities as part of its arsenal.

Security analysts at mobile protection firm ThreatFabric discovered that the threat has operated since February. Primary targets include users in Ukraine, with additional attacks spreading into Central Europe, Western Europe, Russia, and the United Kingdom.

Advanced Keypad Overlays and Extensive Target Scope

The malware monitors at least 169 specific mobile applications across various consumer sectors. Targeted software includes banking utilities, government identification tools, payment gateways, crypto wallets, messaging apps, and two-factor authentication tools.

The data stolen by such mobile malware often ends up on dark web extortion sites. In June 2026, the ShinyHunters ransomware group claimed to have breached the Council of Europe and stolen 297 GB of data, including 409,000 payslips spanning 15 years, 3,700 personnel files, and over 14,000 CVs. The group gave the organization until June 16 to comply with ransom demands before leaking the data, a pattern consistent with the growing monetization of stolen personal information.

Manic deploys transparent overlays directly onto numeric keypads within legitimate financial software. Victims interact with genuine application keypads while transparent layers capture physical screen taps without raising suspicion.

The software logs touch coordinates and uses Android Accessibility services to pass taps back to the underlying application. Consequently, the authentic banking program functions normally, hiding malicious activity from the victim during active sessions.

After securing Android Accessibility and notification access, the agent captures lock screen passcodes, intercepting incoming text messages. The malware also gathers personal files, tracks geographic coordinates, records active screens, and establishes live WebRTC sessions for remote control.

ThreatFabric reports that the system functions as an intelligent user interface keylogger. The code organizes captured keystrokes into clear categories, distinguishing lock screen codes, crypto recovery phrases, passwords, and two-factor authentication codes.

Offline Mesh Relays and Multi-Hop Exfiltration Routes

The most distinctive technical feature of Manic involves its resilient fallback data exfiltration mechanism. Threat actors built a store-and-forward relay system that operates when infected phones cannot reach central command servers directly.

If a compromised device loses internet connectivity, the software encrypts stolen files using advanced encryption algorithms. The system places encrypted data packets into a local queue while searching for nearby compromised smartphones.

The malware scans immediate physical environments for infected peer devices using Wi-Fi Direct and Bluetooth connections. It evaluates surrounding smartphones to determine whether neighboring infected hardware maintains active internet access.

Once the program identifies an online peer, it transfers encrypted data through short-range wireless channels. The receiving smartphone forwards stolen files to the central command server on behalf of the offline phone.

Furthermore, the system supports complex multi-hop communication chains across local device networks. The software configures queued data packets to jump through up to four relay devices to reach remote command infrastructure.

This mesh networking technique enables constant data exfiltration even when the target device operates in locations where there is no mobile connectivity. Moreover, the relay chains hide the original source of the data traffic, making forensic investigations more difficult for those defending the network.

Infrastructure Evolution and Essential Defense Measures

According to the analysis of security researchers, hackers used a variety of technical improvements to change their infrastructure methodically over time. In late May, attackers distributed malware with a simple software wrapper, which looked like a utility program.

By July, the attackers had evolved to include installation wrappers equipped with advanced anti-analysis techniques and an injection script with an in-memory execution property. Developers also rolled out an updated administrative panel and revised application programming interfaces to manage expanded botnet operations.

The swift advancement of this mobile threat demonstrates the increasing risks to mobile banking systems around the world. Cybercriminals constantly work on their automated fraud platforms to avoid traditional endpoint protection and traffic monitoring.

In order to minimize the risk of getting infected, people using their mobile devices should avoid downloading installation files from unofficial third-party sources. Device owners should inspect application permissions carefully, they should deny Accessibility service requests unless required by verified software.

Additionally, users should enable Google Play Protect scanning tools to detect known malicious packages automatically. Promptly revoking unneeded system permissions prevents rogue applications from establishing persistent administrative control over personal smartphones.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.