Interestana
Home/News/Manic Android Malware Steals Data From Offline Phones
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Manic Android Malware Steals Data From Offline Phones

Manic Android Malware Steals Data From Offline Phones

A novel Android malware strain, identified as Manic, has emerged, exhibiting a sophisticated method of data exfiltration that extends to offline devices. This threat operates by infecting nearby, potentially offline, Android phones and leveraging them to relay stolen data to its command-and-control infrastructure. Manic's primary targets include Ukrainian banks, government and identity services, and messaging applications. It also extends its reach to Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications platforms. Security researchers have characterized Manic as a hybrid threat, combining the functionalities of Android banking malware with those of mobile spyware. This dual capability allows it to facilitate financial fraud while simultaneously engaging in extensive surveillance.

The malware's unique infection vector involves exploiting Bluetooth and Wi-Fi Direct functionalities to spread to other devices within proximity. Once a device is infected, Manic can establish a peer-to-peer network with other compromised phones. This network enables the exfiltration of sensitive information, even if the primary infected device lacks direct internet connectivity. The data collected includes banking credentials, personal identifiable information, and potentially classified communications, depending on the targeted application. The malware's persistence and its ability to operate in a decentralized manner make it particularly challenging to detect and eradicate using traditional network-based security measures.

Researchers at Group-IB, who first identified and analyzed Manic, have detailed its operation in a recent report. The analysis indicates that Manic is designed to be stealthy, employing techniques to evade detection by standard antivirus software and mobile security solutions. Its ability to pivot through infected devices creates a complex attack chain, making attribution and mitigation efforts more difficult for cybersecurity professionals. The malware's focus on critical infrastructure and financial services highlights a growing trend in sophisticated mobile threats aimed at high-value targets.

The implications of Manic's capabilities are significant for mobile security. The malware's reliance on local network protocols to bypass internet connectivity requirements for data transfer represents an innovative, albeit malicious, approach to malware propagation and command-and-control. This method could potentially be adopted by other threat actors seeking to circumvent network monitoring and security controls. The ongoing analysis of Manic's code and behavior is crucial for developing effective countermeasures and understanding the evolving landscape of mobile cyber threats.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next