Mobile technology
21.08.2026 09:00

Share with others:

Share

An insidious threat for Android that steals data even without an internet connection

Always install only the apps you need on your Android mobile device and only from official sites.
Always install only the apps you need on your Android mobile device and only from official sites.

Security researchers at ThreatFabric have been closely monitoring the infrastructure of a new Android malware called Manic for some time. The malicious code is installed on at least 169 different applications, including mobile banking, digital identity services, crypto wallets, two-factor authentication applications, and even military and business communication applications. The main focus of the attacks is in Ukraine, but banking applications from a number of European countries, such as Germany, France, Austria, Poland, and other markets, are also among the targets.

Manic combines two areas that usually operate separately: bank fraud and direct espionage. The program can track the location of the device, read notifications, view files and remotely control the phone. The virus spreads through container applications that use names similar to system components of established manufacturers. The latest versions load the code directly into memory and skillfully hide from the list of installed applications.

The PIN interception technique is particularly sophisticated. Instead of displaying fake login pages, the malicious code places a transparent layer over the numeric keypads of the targeted applications. It accurately records every touch on the screen, then abuses accessibility services and repeats the same tap so that the legitimate application works without any noticeable interference. In addition, the malicious code can automatically test already saved passwords on the lock screen. It sorts all entered characters by type on the fly, distinguishing between crypto wallet security words, SMS codes, passwords and regular messages. Attackers can also control the device live via WebRTC and monitor the image from the camera or screen, while showing the user a black screen or fake updates.

The most unusual part of the system is the transmission of stolen information. If the infected phone does not have access to the Internet, it encrypts the stolen data with the AES-GCM algorithm and stores it in a local queue. It then uses Wi-Fi Direct or Bluetooth to find other infected devices nearby and transmits the encrypted packet to them, which then travels up to four intermediate hops to the control server.

Disconnecting the device from the network will not prevent data leakage if another infected phone is nearby. The basic protection therefore remains to consistently avoid installing APK files from unverified sources and be cautious when granting extensive system permissions.


Interested in more from this topic?
android information security cyber security


What are others reading?