Skip to main content
AVOID.NET

Manic Android Banking Trojan

avoid.net/manic-android-banking-trojan0/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·54VzBC…dQcb

Summary

Manic is an active Android malware family first identified by ThreatFabric and Kaspersky in 2026, combining banking-trojan credential theft, spyware, and remote device takeover. It targets 169 Android application package IDs including cryptocurrency wallets, exchanges, banks, authenticators, and government eID services, and employs a novel offline Wi-Fi mesh relay to exfiltrate stolen data through chains of nearby infected devices even without direct internet access. Primary targeting is concentrated on Ukraine, with secondary reach across Russia, Europe, and global fintech and cryptocurrency platforms.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Manic Android Banking Trojan?

Timeline(6 events)

1 February 2026

First Manic-associated infrastructure domains registered, per ThreatFabric analysis.

ThreatFabric

1 March 2026

Manic production C2 services come online in late March to April 2026.

ThreatFabric

1 May 2026

First retained Manic wrapper and implant samples appear in late May 2026, using a booking-app lure.

ThreatFabric / The Hacker News

13 July 2026

Updated Manic wrapper deployed with in-memory DEX loading, enhanced anti-analysis protections, lock-screen secret phishing, and launcher-hiding behavior.

ThreatFabric / The Hacker News

24 July 2026

Manic C2 infrastructure confirmed live, with panel and API active through approximately July 28, 2026.

ThreatFabric / The Hacker News

22 August 2026

ThreatFabric publishes full technical disclosure of Manic. Kaspersky publishes parallel analysis. SecurityWeek, The Hacker News, Security Affairs, and other outlets report on the disclosure.

ThreatFabric / SecurityWeek
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 5 of 6 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 9/19/2026, 5:08:42 PM

last updated: 9/19/2026, 5:10:49 PM

avoid.net — verified advice for a post-truth world