New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones
A newly discovered Android malware family named Manic combines banking fraud with full-scale spyware, and it comes with a trick researchers rarely see in the wild: when an infected phone has no internet connection of its own, it can quietly borrow one from another infected device nearby.
The malware was identified by ThreatFabric’s Mobile Threat Intelligence team, which describes Manic as sitting at the intersection of Android banking trojans and mobile spyware.
Rather than focusing on a single scam, Manic gives its operators a complete fraud toolkit : it can read a victim’s PIN, watch their screen live, hijack banking sessions, and pull files, messages, and location data off the device.
ThreatFabric traced Manic’s infrastructure back to February 2026, with development accelerating through the spring and a more advanced version emerging by July featuring stronger anti-analysis defenses and in-memory code loading.
The malware currently monitors 169 apps, spanning banks, government identity portals, payment services, cryptocurrency wallets and exchanges, authenticator apps, and messaging platforms.
Ukraine is clearly the priority, covering national banks and eID services, but the target list extends into Russia, Poland, Germany, the Czech Republic, Slovakia, and the UK, along with global fintech and crypto platforms
That mix tells its own story. Financial institutions and crypto wallets point to straightforward theft, while the inclusion of government identity apps and both commercial and military-oriented messengers suggests the operators also want insight into a victim’s communications, not just their bank balance.
Most banking trojans steal credentials by throwing up a convincing fake login screen over the real app, a technique known as an overlay attack. Manic largely skips that step. Instead, once it has Accessibility and notification permissions, it places a transparent layer only over the numeric keypad of a genuine banking app, quietly recording where the victim taps.
It then replays those exact taps back to the real app through Android’s Accessibility service, so the transaction goes through normally while the PIN is logged in the background.
The malware applies a similar trick to the lock screen itself, attempting to capture and later reuse the device’s unlock code or pattern. Combined with SMS and notification interception, and live WebRTC screen-sharing sessions that let an operator watch and interact with the phone in real time, Manic effectively gives attackers hands-on remote control of a victim’s device.
The most distinctive part of Manic’s design is how it moves stolen data off the device. When an infected phone cannot reach its command-and-control server directly, it does not give up.
Manic MITRE ATT&CK Matrix (Image Source: ThreatFabric)
Instead, it encrypts the collected data, stores it locally, and searches for another infected phone nearby using Wi-Fi Direct, Bluetooth, or BLE that does have internet access. That second device then forwards the package onward, effectively turning ordinary infected phones into an unwitting mesh network for data exfiltration.
This peer-relay approach means that cutting off a single phone’s internet connection is not enough to stop data from leaking out, as long as another compromised device is within radio range.
Manic’s blend of stealthy PIN capture, deep device takeover, and a self-healing exfiltration network makes it harder to detect and harder to contain than a typical banking trojan.
Device Takeover Fraud Path (Image Source: ThreatFabric)
ThreatFabric’s continued tracking of the campaign, alongside similar 2026 discoveries like the WindRelay NFC relay malware and the human-mimicking Herodotus trojan, points to a broader trend of Android threats layering multiple fraud techniques into a single platform.
Security teams and everyday users alike are advised to avoid sideloading APKs from unofficial sources, scrutinize any app requesting Accessibility permissions, and keep Google Play Protect active, since Manic and similar families rely heavily on these permissions to operate
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones appeared first on Cyber Security News .
cybersecuritynews.com