A new Android malware called Manic can steal passwords, banking details, messages, and other data. Here’s what Android users should know and how to better protect their phones and accounts.
Table of Contents
What Happened With the Manic Android Malware?
ThreatFabric — a mobile security company — analyzed the malware. Researchers found that it combines spyware, banking fraud, and remote phone control.
Manic targets at least 169 banking, government, payment, crypto, messaging, and two-step verification apps. Its main focus appears to be users in Ukraine.
The malware can steal information directly from an infected phone. It may capture passwords, lock-screen codes, messages, files, location data, and login details.
It can also watch the screen and let criminals control the phone remotely.
Manic steals data directly from infected phones, but that is not the only place your information may be at risk.
Your email or personal details may already appear in older data breaches you never heard about. Criminals can reuse that information in phishing or impersonation attempts.
If you are unsure whether your information was leaked elsewhere, automatic monitoring can help you spot problems earlier.
Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Manic Targets and What It Can Steal
ThreatFabric says Manic mainly targets apps used across Central and Western Europe, including the United Kingdom and Russia.
However, banking and government identity apps in Ukraine appear to be the campaign’s main focus.
The malware also targets global payment, cryptocurrency, messaging, and authentication services.
Researchers did not say how many people have been infected.
Once Manic receives certain phone permissions, it can collect several types of information, including:
- Lock-screen PINs and passwords
- Banking and login details
- SMS messages and notification content
- Two-step verification codes
- Files stored on the phone
- Location data
- Recovery phrases that may protect cryptocurrency wallets
- Text typed into apps
This information is stolen from infected devices. The source does not say that Manic publicly leaked the stolen data online.
Futureproof monitors your information for data leaks 24/7 and guides you with clear steps to keep it safer from scams.
Run a free checkHow Manic Can Steal Data and Send It Through Nearby Phones
Researchers do not yet know exactly how Manic first reaches victims.
However, they found that newer versions use a wrapper, which is a small program that delivers the main malware.
After installation, Manic tries to gain Android Accessibility and notification permissions.
Accessibility is designed to help people control their phones. Malware can misuse that access to read screens, track taps, and control apps.
Manic can place a transparent layer over a legitimate app’s keypad. It records where you tap while the real app continues working normally.
That can let criminals capture PINs, passwords, and other sensitive information without showing an obvious fake screen.
Manic also has an unusual backup method for sending stolen data.
If the infected phone cannot reach the criminals’ server, Manic looks for nearby infected devices using Wi-Fi Direct or Bluetooth.
A nearby infected phone with internet access can then relay the stolen information.
Researchers say the malware can even pass information through several infected devices before it reaches the server.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
