{"id":26036,"date":"2026-08-31T13:18:45","date_gmt":"2026-08-31T17:18:45","guid":{"rendered":"https:\/\/me-en.kaspersky.com\/blog\/?p=26036"},"modified":"2026-08-31T21:37:12","modified_gmt":"2026-08-31T17:37:12","slug":"manic-android-trojan","status":"publish","type":"post","link":"https:\/\/me-en.kaspersky.com\/blog\/manic-android-trojan\/26036\/","title":{"rendered":"No internet? The Manic Trojan can still steal your data"},"content":{"rendered":"<p>Cybersecurity researchers have <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices\/\" target=\"_blank\" rel=\"noopener nofollow\">discovered<\/a> a new family of Android malware, and it goes by the name of Manic. It lets criminals spy on their victims, steal banking credentials, and take remote control of infected devices.<\/p>\n<p>But its most unusual trick is this: Manic can send stolen data back to attackers even when the given device has no internet connection. Apparently, random mobile internet outages seem to get in cybercriminals\u2019 way just as much as anyone else\u2019s, so the actors behind Manic came up with an unusual workaround.<\/p>\n<p>People across a wide range of European countries are at risk, from Russia to the United Kingdom. In this post, we walk through what this Trojan can actually do, how it smuggles stolen data out to attackers, and <a href=\"https:\/\/me-en.kaspersky.com\/mobile-security?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kisa____3d7d2c33c4c17a10\" target=\"_blank\" rel=\"noopener\">how you can protect your Android device from Manic and other similar threats<\/a>.<\/p>\n<h2>How Manic spreads, and who\u2019s at risk<\/h2>\n<p>Researchers haven\u2019t yet pinned down exactly how attackers are getting Manic onto people\u2019s devices. Typically, malware like this spreads through channels like:<\/p>\n<ul>\n<li>Infected apps on legitimate app stores<\/li>\n<li>Malicious APK files shared on pirate websites<\/li>\n<li>Download links sent through messaging apps and email<\/li>\n<li>Scam sites<\/li>\n<\/ul>\n<p>Google has <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices\/\" target=\"_blank\" rel=\"noopener nofollow\">told journalists<\/a> it hasn\u2019t found any trace of Manic spreading through apps on the Google Play Store. That suggests people are most likely installing infected apps from unofficial sources.<\/p>\n<p>Experts have traced the beginnings of the attackers\u2019 infrastructure for this campaign to February 2026. The earliest samples of the malware itself turned up in late May of this year. Since then, the criminals behind the Trojan have refined the ways it hides from detection on a victim\u2019s device.<\/p>\n<p>Manic currently combines the powers of a banking Trojan, spyware, and a remote-access tool that lets an attacker control the device. Attackers are especially interested in data from sources like:<\/p>\n<ul>\n<li>Banking apps and payment services<\/li>\n<li>Official government apps<\/li>\n<li>Crypto wallets and cryptocurrency exchanges<\/li>\n<li>Two-factor authentication apps<\/li>\n<li>Text messages and notifications: mainly the one-time codes used to verify logins or approve transactions<\/li>\n<\/ul>\n<p>By looking at which banking apps Manic targets, researchers have been able to work out which countries it has in its sights. It turns out its reach is broad, covering Austria, the Czech Republic, Estonia, France, Germany, Lithuania, the Netherlands, Poland, Russia, Slovakia, Spain, Ukraine, and the United Kingdom.<\/p>\n<h2>Stolen passwords, intercepted codes, remote control: what Manic can actually do<\/h2>\n<p>Let\u2019s look at exactly what information Manic steals, and how it manages to get it. The malware\u2019s main trick relies on abusing Android\u2019s <a href=\"https:\/\/www.kaspersky.com\/blog\/android-most-dangerous-features\/49418\/\" target=\"_blank\" rel=\"noopener nofollow\">Accessibility services<\/a>, a set of built-in features designed to help users with visual impairments. Used as intended, these features are genuinely helpful for people with vision loss. But criminals have long been quietly exploiting the very same tools for their own purposes.<\/p>\n<p>Once a user grants an app permission to use Accessibility services, that app can \u201csee\u201d the text and buttons on the screen, interact with them, scroll through pages, and carry out actions automatically \u2014 all as if a user were doing it themselves. Attackers use this to read messages on screen, quietly grant the malware extra permissions, interfere with attempts to uninstall it, switch off security protections, or control other apps without the victim ever noticing.<\/p>\n<p>With Manic, this abuse of Accessibility services is paired with the Trojan\u2019s own advanced capabilities. It can generate an invisible keyboard that overlays the phone\u2019s real one. When a user types their password to log in to a banking app, Manic records exactly which keys they pressed. Then it uses Accessibility services to instantly replay that same keystroke on the actual app keyboard.<\/p>\n<div id=\"attachment_56324\" style=\"width: 826px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2026\/08\/31211942\/manic-android-trojan-01.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-56324\" class=\"wp-image-56324 size-full\" title=\"Manic generates a transparent capture layer that covers the phone's keyboard\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/37\/2026\/08\/31211942\/manic-android-trojan-01.jpg\" alt=\"Manic generates a transparent capture layer that covers the phone's keyboard \" width=\"816\" height=\"505\"><\/a><p id=\"caption-attachment-56324\" class=\"wp-caption-text\">Manic generates a transparent capture layer that covers the phone\u2019s keyboard, recording each tap and relaying it to the real keyboard. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-manic-android-malware-can-exfiltrate-data-through-nearby-devices\/\" target=\"_blank\" rel=\"nofollow noopener\">Source<\/a><\/p><\/div>\n<p>This means attackers don\u2019t have to build a fake login screen for every single app they want to target. Because Manic works as an invisible layer sitting on top of the genuine app, everything looks and behaves as usual, so a phone owner has no reason to suspect they\u2019re handing over their PIN or password to a criminal.<\/p>\n<p>Manic doesn\u2019t simply log everything a user types, either. It automatically recognizes what kind of information it has just captured and sorts it into categories: passwords, email logins, four-to-six-digit SMS codes, strings of characters that look like crypto wallet seed phrases, and phone unlock codes or pattern locks. Alongside the captured text itself, Manic also records which app it came from, when it was entered, whether the user typed it manually or used autofill, and whether that app is on its hit list.<\/p>\n<p>Manic\u2019s abilities don\u2019t stop at collecting information. Using Accessibility services once again, it also lets attackers take remote control of an infected device. To conceal this activity, Manic can show a black screen or fake a system update.<\/p>\n<p>On top of Accessibility services, the malware also asks for permission to read text messages and notifications. That lets attackers intercept two-factor authentication codes and one-time verification codes before a victim even has a chance to type them into the app.<\/p>\n<p>Put together, this hands attackers not just passwords, banking credentials, and verification codes, but the ability to remotely control the victim\u2019s phone as well.<\/p>\n<h2>Even being offline won\u2019t save you from data theft<\/h2>\n<p>Manic\u2019s original method for relaying stolen data off the device and back to the attackers deserves a separate mention. Even today, devices get knocked offline more often than people might expect, and Manic\u2019s creators built a workaround specifically for such situations.<\/p>\n<p>Normally, malware like this collects information on the device and sends it straight to a server controlled by the attackers. But what happens when the infected device has no direct internet access, or can\u2019t reach the command-and-control server for some other reason?<\/p>\n<p>In that case, Manic simply stores the stolen data on the device and starts scanning nearby for other infected phones it can reach over Wi-Fi or Bluetooth. If it finds one with internet access, it hands over the encrypted data to that phone, which then forwards it on to the attackers\u2019 server.<\/p>\n<p>But it doesn\u2019t stop there. Data can hop across a chain of infected devices. By default, Manic allows up to four of these relay devices in the chain. If no suitable device is nearby, the data simply stays on the original phone, and Manic tries again later.<\/p>\n<h2>How to protect your phone from Manic and other banking Trojans<\/h2>\n<p>Android malware keeps getting more sophisticated. That makes it worth remembering\u00a0\u2014 and actually following\u00a0\u2014 a few basic digital hygiene habits for Android phone and tablet users:<\/p>\n<ul>\n<li>Avoid installing apps from unofficial sources.<\/li>\n<li>Don\u2019t grant apps permission to use Accessibility services unless this is absolutely necessary and you understand exactly why they need it.<\/li>\n<li>Install reliable security software on all your devices, run scans regularly, and take its warnings and recommendations seriously. We recommend <a href=\"https:\/\/me-en.kaspersky.com\/mobile-security?icid=me-en_kdailyplacehold_acq_ona_smm__onl_b2c_kdaily_wpplaceholder_sm-team___kisa____3d7d2c33c4c17a10\" target=\"_blank\" rel=\"noopener\">Kaspersky for Android<\/a>. Our Android security apps are temporarily unavailable on the Google Play Store, so to install them on an Android device we recommend using an alternative app store or installing the APK file manually from <a href=\"https:\/\/support.kaspersky.com\/common\/beforeinstall\/16085\" target=\"_blank\" rel=\"noopener\">our website<\/a>. A full step-by-step guide is available in our post, <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-install-kaspersky-apps-from-alternative-stores\/52889\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>How to install or update Kaspersky apps for Android in 2026<\/strong><\/a>.<\/li>\n<\/ul>\n<blockquote><p>Malware doesn\u2019t just target smartphones; it feels at home on other Android-powered devices too \u2014 from streaming boxes to\u2026 cars. Check out the details in our related posts:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/car-botnet-malware-for-head-units-with-android\/56296\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Botnet on the road: the first Trojan for car head units<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/qualcomm-cve-2026-25262\/55811\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Qualcomm vulnerability: phone repairs and car maintenance are no longer safe<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/android-tv-botnet\/55799\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Is your TV box renting out your network?<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/beatbanker-btmob-android-malware-disguised-starlink-inss-reembolso\/55401\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Android Trojan posing as government services and Starlink apps<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/growing-2026-android-threats-and-protection\/55191\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>The perfect storm of Android threats<\/strong><\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kisa-generic-3\">\n","protected":false},"excerpt":{"rendered":"<p>It steals passwords, banking credentials, and verification codes, and lets attackers control a smartphone remotely. Here&#8217;s why this new Android threat is so dangerous, and how it manages to transfer stolen data home.<\/p>\n","protected":false},"author":2726,"featured_media":26042,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1486],"tags":[1047,2242,105,2629,702,1505,22,36,682,692,2794],"class_list":["post-26036","post","type-post","status-publish","format-standard","has-post-thumbnail","category-threats","tag-2fa","tag-accessibility","tag-android","tag-bankers","tag-banking-trojans","tag-cryptocurrencies","tag-google","tag-malware-2","tag-spyware","tag-trojans","tag-two-factor-authentication"],"hreflang":[{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/manic-android-trojan\/26036\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/manic-android-trojan\/31012\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/manic-android-trojan\/30842\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/manic-android-trojan\/42585\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/manic-android-trojan\/56323\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/manic-android-trojan\/30987\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/manic-android-trojan\/36506\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/manic-android-trojan\/36417\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/me-en.kaspersky.com\/blog\/tag\/android\/","name":"Android"},"_links":{"self":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26036","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=26036"}],"version-history":[{"count":3,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26036\/revisions"}],"predecessor-version":[{"id":26041,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/26036\/revisions\/26041"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/26042"}],"wp:attachment":[{"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=26036"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=26036"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/me-en.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=26036"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}