Manic malware steals bank PINs and spies on phones
A new Android malware called Manic combines banking fraud with full spyware. Researchers at ThreatFabric say it can capture a victim's PIN, watch their screen live, and pull files, messages, and location off the phone.
- Report priority
- Medium
- Targets
- Cryptocurrency wallets and exchanges+1 more
How it works
Once Manic tricks a victim into granting Accessibility and notification permissions, it places an invisible layer over just the number pad in a real banking app, records every tap, then replays those taps back through Android's Accessibility service so the payment still goes through while the PIN is logged.
What to do
There is no version number to check since this is malware, not a software flaw, so look instead at which apps on your phone have Accessibility service access under Settings, especially any app you did not install from Google Play, and watch for a banking, government ID, payment, crypto, authenticator, or messaging app behaving oddly or asking for screen-sharing.
Only install banking, government ID, and crypto apps from Google Play, keep Google Play Protect turned, and revoke Accessibility and notification access from any app you do not recognize or did not deliberately grant it. ThreatFabric's advisory has no separate consumer patch to install.
Technical details
Affected software: Cryptocurrency wallets and exchanges, Authenticator apps
ThreatFabric tracks Manic's infrastructure back to February 2026, with a more advanced July build adding stronger anti-analysis defenses and in-memory code loading. It monitors 169 targeted apps across banking, government identity, payments, crypto, authenticator, and messaging categories. Beyond PIN-pad overlay capture and lock-screen code capture, it intercepts SMS and notifications and supports live WebRTC screen-sharing for hands-on remote control. Its distinguishing feature is peer relay exfiltration: when a device has no direct connection to the command-and-control server, it encrypts stolen data locally and forwards it through another infected phone in Wi-Fi Direct, Bluetooth, or BLE range, forming a self-healing mesh that survives cutting off any single device's internet access.
References
- threatfabric.com · manic-blend-between-banking-malware-and-spyware Cyber Security News
- any.run · threat-intelligence-lookup Cyber Security News
- thehackernews.com · toxicpanda-20-and-golddigger-expand.html TheHackerNews
- thehackernews.com · manic-android-malware-exfiltrates-data.html TheHackerNews
- bleepingcomputer.com · new-manic-android-malware-can-exfiltrate-data-through-nearby-devices BleepingComputer
- gbhackers.com · toxicpanda-2-0-steals-pins GBHackers
- infosecurity-magazine.com · new-linux-botnet-evooo1bot-victims Infosecurity Magazine
- infosecurity-magazine.com · fake-bank-of-america-phishing-scam Infosecurity Magazine
- scworld.com · new-android-banking-trojan-toxicpanda-2-0-expands-victim-targeting SC World