The Android Malware That Spreads Through Your Offline Phone: How Manic Bypasses Internet Disconnection
A newly discovered Android malware strain called Manic has introduced an unusual technique that allows it to steal data from phones even when they're disconnected from the internet, by using nearby infected devices as relay points. The malware, which has been actively targeting Ukrainian banks, government identity services, and financial institutions across Russia and Europe since February 2026, combines banking fraud capabilities with broad surveillance features that security researchers say represent a significant evolution in mobile threats.
What Makes Manic Different From Other Android Banking Malware?
Manic sits at the intersection of two threat categories: traditional Android banking malware and mobile spyware. Unlike typical mobile malware that requires internet connectivity to send stolen data back to attackers, Manic can operate in a mesh network environment. If an infected phone loses internet access, the malware can find another compromised Android device nearby and relay the stolen information through that device instead.
The malware monitors 169 different banking apps, payment services, cryptocurrency wallets, government identity applications, and messaging platforms. The majority of targeted apps are used in Ukraine, but the threat also extends to Russia, Central Europe, Western Europe, and the United Kingdom. This broad targeting suggests attackers are interested in both financial fraud and real-time surveillance of victims' communications and location data.
How Does the Offline Relay Mechanism Actually Work?
The most unusual aspect of Manic is its store-and-forward relay system. When an infected phone cannot connect to the attacker's command-and-control server, it stages collected files and command results in an encrypted format and places them in a local queue. The malware then searches for other infected devices nearby using Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT protocols. If a peer device is found, the encrypted package is relayed to it and forwarded toward the attacker's infrastructure.
The system supports multi-hop routes, meaning queued data can be configured to pass through up to four relay hops by default before reaching the attacker. If no peers are found, the data remains in the queue and the process retries later. This design means that simply disconnecting an infected device from the internet does not necessarily prevent data exfiltration, as Manic can weaponize another compromised Android device as a gateway.
What Specific Capabilities Does Manic Possess?
Beyond its relay mechanism, Manic includes a comprehensive toolkit of surveillance and fraud features:
- Credential Theft: Intercepts keypad interactions to collect passwords, one-time codes, and recovery phrases from targeted apps
- Keystroke Logging: Leverages Android accessibility services as a "UI keylogger" to classify and record text along with the specific app being used
- PIN Code Capture: Serves a transparent overlay atop legitimate numeric keypads in banking apps, recording exact tap positions without displaying a fake interface
- Remote Surveillance: Monitors the screen and interacts with the device remotely over WebRTC sessions, records current coordinates and timestamps, and takes screenshots
- Data Exfiltration: Exports contacts, call history, SMS messages, notifications, and lists of installed apps
- Device Control: Locks the screen through accessibility services, attempts to disable Google Play Protect, and removes itself from the launcher
The PIN code capture technique is particularly sophisticated. When a user taps on the transparent overlay, Manic records the exact tap position and nearby UI element. It then briefly turns off touch interception and replicates the tap on the actual keypad at the same position using accessibility services APIs. This allows the targeted banking app to function normally while the threat actor obtains the PIN code without displaying a fake banking interface.
How Is Manic Distributed and What's Its Development Timeline?
Manic is distributed via phishing sites and dropper apps that impersonate utility applications. Security researchers at ThreatFabric tracked the malware family's activity dating back to February 2026, when the first domain was registered with a fabricated persona. Active development began shortly after, with the first wrapper using a booking app lure appearing in May 2026 and the implant following by the end of May.
Interestingly, development efforts were abandoned from late June to mid-July 2026, but signs of a second deployment emerged around July 13. The newer iteration incorporated stronger anti-analysis checks and the ability to phish lock screen secrets. A corresponding control panel and API went live between July 24 and 28. The package names linked to the wrapper and implant include tech.intel.dialer.updater, org.honor.secure.helper, org.lenovo.storage.processor, and dev.huawei.media.helper.
How Are Banks Adapting Their Fraud Detection Strategies?
While Manic represents a technical threat to mobile devices, banks are simultaneously facing a different but related challenge: social engineering attacks where customers themselves authorize fraudulent payments after being manipulated by criminals. According to ThreatMark's Fraud Readiness Benchmark 2026, 55 percent of financial institutions surveyed said social engineering is involved in most of their fraud cases.
This shift is forcing banks to move beyond traditional fraud detection methods that look for stolen credentials or suspicious devices. Instead, fraud teams are increasingly paying attention to customer behavior during banking sessions, looking for signs that a customer may be under pressure or following another person's instructions before money leaves the account.
Behavioral intelligence technology is emerging as a key tool in this effort. It establishes patterns in how a customer interacts with a banking service and detects changes during a session. Signals may include unusual hesitation, repeated steps, or an uncharacteristically large transfer to a new payee. Eighty-three percent of respondents rated behavioral intelligence as effective for detecting social engineering, though adoption remains limited with only 18 percent of institutions currently using the technology.
How to Strengthen Your Mobile Security Against Threats Like Manic
- Disable Accessibility Services: Review which apps have permission to use accessibility services on your Android device. Manic abuses these permissions extensively, so restrict access to only trusted applications that genuinely need them
- Monitor App Permissions: Regularly audit which apps have notification permissions and location access. Manic uses these to monitor your activity, so remove permissions from apps that don't require them
- Verify App Sources: Only download apps from the official Google Play Store and verify app publishers before installation. Manic is distributed through phishing sites and dropper apps impersonating legitimate utilities
- Enable Google Play Protect: Keep Google Play Protect enabled on your device. While Manic attempts to disable it, an active protection system provides an additional layer of defense against malicious apps
- Use Strong Authentication: Enable multi-factor authentication on all banking and financial apps. This adds protection even if Manic captures your password or PIN code
The evolution of Manic between May and July 2026, including stronger anti-analysis measures and lock-secret phishing capabilities, indicates that the malware remains under active development and continues to expand its capabilities.
What Does the Broader Market Outlook Tell Us About Digital Risk?
The emergence of sophisticated threats like Manic is occurring within a rapidly expanding digital risk protection market. The global digital risk protection market is projected to grow from USD 5.38 billion in 2025 to USD 36.59 billion by 2035, representing a compound annual growth rate of 21.13 percent. This explosive growth reflects organizations' increasing recognition that threats extend far beyond traditional network boundaries.
The market expansion is driven by expanding digital footprints, rising phishing and impersonation attacks, cloud adoption, and growing exposure across social media, e-commerce, and third-party platforms. Organizations are prioritizing brand reputation, data protection, regulatory compliance, and faster threat response. Increasing use of AI-powered monitoring is further strengthening demand for proactive digital risk management.
North America is expected to generate the largest revenue during the forecast period, while Asia Pacific is expected to grow at the fastest rate. This regional variation reflects differences in digital infrastructure maturity and regulatory pressure across markets.
"The evolution observed between May and July 2026, including stronger anti-analysis measures and lock-secret phishing, indicates that Manic remains under active development and continues to expand its capabilities," stated ThreatFabric in their technical analysis.
ThreatFabric, Security Research Organization
The combination of sophisticated mobile malware like Manic and the shift toward behavioral fraud detection reflects a security landscape where threats are becoming more targeted and harder to detect using traditional methods. Organizations must now balance technical defenses with behavioral monitoring and user education to protect against both automated attacks and socially engineered fraud.