{"id":8065,"date":"2026-08-21T09:00:00","date_gmt":"2026-08-21T07:00:00","guid":{"rendered":"https:\/\/viva.racunalniske-novice.com\/zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave\/"},"modified":"2026-08-21T09:00:00","modified_gmt":"2026-08-21T07:00:00","slug":"zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave","status":"publish","type":"post","link":"https:\/\/viva.racunalniske-novice.com\/en\/insidious-android-threat-that-steals-data-even-without-an-internet-connection\/","title":{"rendered":"An insidious threat for Android that steals data even without an internet connection"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Security researchers at ThreatFabric have been closely monitoring the infrastructure of a new Android malware called Manic for some time. The malicious code is installed on at least 169 different applications, including mobile banking, digital identity services, crypto wallets, two-factor authentication applications, and even military and business communication applications. The main focus of the attacks is in Ukraine, but banking applications from a number of European countries, such as Germany, France, Austria, Poland, and other markets, are also among the targets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Manic combines two areas that usually operate separately: bank fraud and direct espionage. The program can track the location of the device, read notifications, view files and remotely control the phone. The virus spreads through container applications that use names similar to system components of established manufacturers. The latest versions load the code directly into memory and skillfully hide from the list of installed applications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The PIN interception technique is particularly sophisticated. Instead of displaying fake login pages, the malicious code places a transparent layer over the numeric keypads of the targeted applications. It accurately records every touch on the screen, then abuses accessibility services and repeats the same tap so that the legitimate application works without any noticeable interference. In addition, the malicious code can automatically test already saved passwords on the lock screen. It sorts all entered characters by type on the fly, distinguishing between crypto wallet security words, SMS codes, passwords and regular messages. Attackers can also control the device live via WebRTC and monitor the image from the camera or screen, while showing the user a black screen or fake updates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most unusual part of the system is the transmission of stolen information. If the infected phone does not have access to the Internet, it encrypts the stolen data with the AES-GCM algorithm and stores it in a local queue. It then uses Wi-Fi Direct or Bluetooth to find other infected devices nearby and transmits the encrypted packet to them, which then travels up to four intermediate hops to the control server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Disconnecting the device from the network will not prevent data leakage if another infected phone is nearby. The basic protection therefore remains to consistently avoid installing APK files from unverified sources and be cautious when granting extensive system permissions.<\/p>","protected":false},"excerpt":{"rendered":"<p>Varnostni raziskovalci podjetja ThreatFabric \u017ee dlje \u010dasa podrobno spremljajo infrastrukturo novega \u0161kodljivega programa za operacijski sistem Android, imenovanega Manic. Zlonamerna koda je name\u0161\u010dena na vsaj 169 razli\u010dnih aplikacij, med katerimi so mobilne banke, storitve digitalne identitete, kripto denarnice, aplikacije za dvostopenjsko preverjanje ter celo voja\u0161ki in poslovni komunikacijski programi. Glavno \u017eari\u0161\u010de napadov je v Ukrajini, [&hellip;]<\/p>","protected":false},"author":2,"featured_media":0,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[50],"tags":[128,478,482],"class_list":["post-8065","post","type-post","status-publish","format-standard","hentry","category-telefonija","tag-android","tag-informacijska-varnost","tag-kibernetska-varnost"],"acf":{"subtitle":"","heading":"","summary":"Nova \u0161kodljiva koda za Android brez internetne povezave lahko ukradene podatke prepo\u0161lje prek Bluetootha ali Wi-Fi Direct povezave na druge blizu le\u017ee\u010de oku\u017eene telefone.","thumbnail_small":"https:\/\/racunalniske-novice.com\/wp-content\/uploads\/2020\/09\/280920_alienmalware-560x315.jpg","thumbnail_large":"https:\/\/racunalniske-novice.com\/wp-content\/uploads\/2020\/09\/280920_alienmalware.jpg","thumbnail_caption":"Na va\u0161o mobilno napravo Android vedno name\u0161\u010dajte zgolj aplikacije, ki jih potrebujete in zgolj iz uradnih mest.","gallery":"","video_gallery":null,"author":"","links":null,"sources":[{"title":"hwupgrade","url":"https:\/\/www.hwupgrade.it\/news\/sicurezza-software\/un-malware-android-trafuga-i-dati-anche-a-telefono-scollegato-rimbalzando-fra-i-vicini_158023.html"}],"skip_language":[]},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.8 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Zahrbtna gro\u017enja za Android, ki podatke krade celo brez internetne povezave - Ra\u010dunalni\u0161ke novice<\/title>\n<meta name=\"description\" content=\"Nova \u0161kodljiva koda za Android brez internetne povezave lahko ukradene podatke prepo\u0161lje prek Bluetootha ali Wi-Fi Direct povezave na druge blizu le\u017ee\u010de oku\u017eene telefone.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/viva.racunalniske-novice.com\/en\/wp-json\/wp\/v2\/posts\/8065\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Zahrbtna gro\u017enja za Android, ki podatke krade celo brez internetne povezave - Ra\u010dunalni\u0161ke novice\" \/>\n<meta property=\"og:description\" content=\"Varnostni raziskovalci podjetja ThreatFabric \u017ee dlje \u010dasa podrobno spremljajo infrastrukturo novega \u0161kodljivega programa za operacijski sistem Android, imenovanega Manic. Zlonamerna koda je name\u0161\u010dena na vsaj 169 razli\u010dnih aplikacij, med katerimi so mobilne banke, storitve digitalne identitete, kripto denarnice, aplikacije za dvostopenjsko preverjanje ter celo voja\u0161ki in poslovni komunikacijski programi. Glavno \u017eari\u0161\u010de napadov je v Ukrajini, [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/viva.racunalniske-novice.com\/en\/insidious-android-threat-that-steals-data-even-without-an-internet-connection\/\" \/>\n<meta property=\"og:site_name\" content=\"Ra\u010dunalni\u0161ke novice\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-21T07:00:00+00:00\" \/>\n<meta name=\"author\" content=\"sinusiks\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"sinusiks\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave\/\",\"url\":\"https:\/\/viva.racunalniske-novice.com\/zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave\/\",\"name\":\"Zahrbtna gro\u017enja za Android, ki podatke krade celo brez internetne povezave - Ra\u010dunalni\u0161ke novice\",\"isPartOf\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#website\"},\"datePublished\":\"2026-08-21T07:00:00+00:00\",\"dateModified\":\"2026-08-21T07:00:00+00:00\",\"author\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4\"},\"breadcrumb\":{\"@id\":\"https:\/\/viva.racunalniske-novice.com\/zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/viva.racunalniske-novice.com\/zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/viva.racunalniske-novice.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Zahrbtna gro\u017enja za Android, ki podatke krade celo brez internetne povezave\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#website\",\"url\":\"https:\/\/viva.racunalniske-novice.com\/en\/\",\"name\":\"Ra\u010dunalni\u0161ke novice\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/viva.racunalniske-novice.com\/en\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4\",\"name\":\"sinusiks\",\"sameAs\":[\"https:\/\/ml.racunalniske-novice.com\"],\"url\":\"https:\/\/viva.racunalniske-novice.com\/en\/author\/sinusiks\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Zahrbtna gro\u017enja za Android, ki podatke krade celo brez internetne povezave - Ra\u010dunalni\u0161ke novice","description":"Nova \u0161kodljiva koda za Android brez internetne povezave lahko ukradene podatke prepo\u0161lje prek Bluetootha ali Wi-Fi Direct povezave na druge blizu le\u017ee\u010de oku\u017eene telefone.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/viva.racunalniske-novice.com\/en\/wp-json\/wp\/v2\/posts\/8065","og_locale":"en_US","og_type":"article","og_title":"Zahrbtna gro\u017enja za Android, ki podatke krade celo brez internetne povezave - Ra\u010dunalni\u0161ke novice","og_description":"Varnostni raziskovalci podjetja ThreatFabric \u017ee dlje \u010dasa podrobno spremljajo infrastrukturo novega \u0161kodljivega programa za operacijski sistem Android, imenovanega Manic. Zlonamerna koda je name\u0161\u010dena na vsaj 169 razli\u010dnih aplikacij, med katerimi so mobilne banke, storitve digitalne identitete, kripto denarnice, aplikacije za dvostopenjsko preverjanje ter celo voja\u0161ki in poslovni komunikacijski programi. Glavno \u017eari\u0161\u010de napadov je v Ukrajini, [&hellip;]","og_url":"https:\/\/viva.racunalniske-novice.com\/en\/insidious-android-threat-that-steals-data-even-without-an-internet-connection\/","og_site_name":"Ra\u010dunalni\u0161ke novice","article_published_time":"2026-08-21T07:00:00+00:00","author":"sinusiks","twitter_card":"summary_large_image","twitter_misc":{"Written by":"sinusiks","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/viva.racunalniske-novice.com\/zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave\/","url":"https:\/\/viva.racunalniske-novice.com\/zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave\/","name":"Zahrbtna gro\u017enja za Android, ki podatke krade celo brez internetne povezave - Ra\u010dunalni\u0161ke novice","isPartOf":{"@id":"https:\/\/viva.racunalniske-novice.com\/en\/#website"},"datePublished":"2026-08-21T07:00:00+00:00","dateModified":"2026-08-21T07:00:00+00:00","author":{"@id":"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4"},"breadcrumb":{"@id":"https:\/\/viva.racunalniske-novice.com\/zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/viva.racunalniske-novice.com\/zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/viva.racunalniske-novice.com\/zahrbtna-groznja-za-android-ki-podatke-krade-celo-brez-internetne-povezave\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/viva.racunalniske-novice.com\/en\/"},{"@type":"ListItem","position":2,"name":"Zahrbtna gro\u017enja za Android, ki podatke krade celo brez internetne povezave"}]},{"@type":"WebSite","@id":"https:\/\/viva.racunalniske-novice.com\/en\/#website","url":"https:\/\/viva.racunalniske-novice.com\/en\/","name":"Ra\u010dunalni\u0161ke novice","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/viva.racunalniske-novice.com\/en\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/viva.racunalniske-novice.com\/en\/#\/schema\/person\/afb62e36efa34516d50249517e4cdbb4","name":"sinusiks","sameAs":["https:\/\/ml.racunalniske-novice.com"],"url":"https:\/\/viva.racunalniske-novice.com\/en\/author\/sinusiks\/"}]}},"_links":{"self":[{"href":"https:\/\/viva.racunalniske-novice.com\/en\/wp-json\/wp\/v2\/posts\/8065","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/viva.racunalniske-novice.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/viva.racunalniske-novice.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/en\/wp-json\/wp\/v2\/comments?post=8065"}],"version-history":[{"count":0,"href":"https:\/\/viva.racunalniske-novice.com\/en\/wp-json\/wp\/v2\/posts\/8065\/revisions"}],"wp:attachment":[{"href":"https:\/\/viva.racunalniske-novice.com\/en\/wp-json\/wp\/v2\/media?parent=8065"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/en\/wp-json\/wp\/v2\/categories?post=8065"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/viva.racunalniske-novice.com\/en\/wp-json\/wp\/v2\/tags?post=8065"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}