Interestana
Home/News/Manic Android Malware Exfiltrates Data Via Nearby Devices
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Manic Android Malware Exfiltrates Data Via Nearby Devices

A newly identified Android malware, dubbed Manic, has been discovered employing a sophisticated fallback data exfiltration technique that utilizes nearby infected devices to transmit stolen information. This novel approach allows the malware to bypass traditional network-based exfiltration methods, making it more challenging to detect and block. The Manic malware primarily targets users across multiple European countries, indicating a geographically focused campaign. Its primary objective appears to be the theft of sensitive user data, which can then be relayed through a chain of compromised devices. This method of relaying data through intermediary infected devices is a significant escalation in the capabilities of mobile malware, as it creates a decentralized network for data transfer.

Researchers at Google's Threat Analysis Group (TAG) first observed the Manic malware in late 2023. The malware is distributed through various social engineering tactics, often masquerading as legitimate applications or updates. Once installed, Manic operates stealthily, collecting a range of sensitive data including contact lists, SMS messages, call logs, device information, and potentially credentials for financial applications. The malware's ability to communicate with a command-and-control (C2) server allows it to receive instructions and upload the exfiltrated data. However, the fallback mechanism is particularly concerning. If direct communication with the C2 server is hindered, Manic can connect to other devices already infected with the same malware. It then uses these nearby infected devices as relays to transmit the stolen data, effectively creating a peer-to-peer network for exfiltration. This distributed approach makes it difficult to pinpoint the origin of the data transfer and complicates efforts to disrupt the malware's operations.

The implications of this multi-hop exfiltration technique are substantial for cybersecurity. It means that a single infected device might not be the ultimate destination for the stolen data, but rather a node in a larger, interconnected network of compromised devices. This complicates network monitoring and incident response, as security teams may need to track data flow across multiple potentially untrusted devices. The targeting of European countries suggests a specific regional focus for this campaign, though the underlying technology could be adapted for global distribution. The ongoing evolution of mobile malware, particularly in its data exfiltration strategies, underscores the persistent threat to user privacy and data security on Android devices. Security researchers continue to monitor Manic and similar threats, urging users to exercise caution when downloading applications and to keep their devices updated with the latest security patches. The discovery of Manic highlights the need for advanced detection mechanisms that can identify anomalous data flows and peer-to-peer communication patterns indicative of such sophisticated malware operations.

Google TAG's analysis indicates that the threat actor behind Manic has been active since at least 2021, with previous campaigns focusing on different malware families. The shift to Manic and its advanced exfiltration capabilities suggests a growing sophistication and adaptation by the group. The malware's ability to persist on a device and conduct covert data theft over extended periods poses a significant risk to individuals and potentially to organizations if corporate data is compromised. The European focus may be due to specific geopolitical or economic motivations of the threat actor, or it could be a testing ground for a broader deployment. The technical details of the peer-to-peer exfiltration are still under active investigation, but the principle involves infected devices broadcasting their availability to act as relays and other infected devices sending data to these relays. This creates a resilient and hard-to-trace data pipeline for the attackers.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next