Manic (Android Banking Trojan / Crypto-Wallet-Targeting Malware)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
Summary
Manic is an active Android malware family, publicly disclosed by the Dutch mobile-threat intelligence firm ThreatFabric on August 20, 2026 and separately covered by Kaspersky, that combines banking-trojan credential theft with spyware and full device-takeover capabilities. It monitors 169 Android app package IDs — including banks, payment apps, cryptocurrency wallets and exchanges, government eID services, authenticator apps, messengers, browsers and email clients — and is notable for an invisible-overlay keystroke capture technique paired with Accessibility-service replay, plus a novel offline Wi-Fi/Bluetooth mesh exfiltration mechanism that relays stolen data through other nearby infected phones even when the source device has no internet access. Manic is not a company or product to be trusted but an active criminal threat; it is indexed here as a risk entity so that crypto holders on Android can recognize and avoid it.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(8 events)
February 2026
First infrastructure associated with the Manic campaign (domain registration under a fabricated persona) is registered, marking the earliest traced activity of the malware family.
ThreatFabric / BleepingComputerMarch 2026
Development and production services supporting the Manic campaign begin to come online, per ThreatFabric's infrastructure timeline (dated to late March/April 2026).
ThreatFabricMay 2026
The first retained malware wrapper and implant appear, using a booking-app lure for initial distribution.
ThreatFabric / The Hacker NewsJuly 2026
Following a development hiatus, a reworked Manic build is deployed with stronger anti-analysis protections, in-memory DEX loading, and new lock-screen secret theft capability; a new operator panel/API is also introduced.
ThreatFabric / The Hacker News20 August 2026
ThreatFabric publicly discloses the Manic malware family in a technical blog post; the disclosure is simultaneously covered by The Hacker News and BleepingComputer.
The Hacker News20 August 2026
BleepingComputer publishes coverage of Manic's Wi-Fi/Bluetooth mesh exfiltration technique, including Google's statement that no apps containing the malware were found on Google Play.
BleepingComputerAugust 2026
Kaspersky publishes its own analysis of Manic on the Kaspersky Daily blog, corroborating ThreatFabric's findings on offline data exfiltration and credential theft.
Kaspersky Daily31 August 2026
eSecurity Planet publishes further coverage summarizing Manic's bank-account-draining capability and offline mesh exfiltration.
eSecurity Planetmodel: claude-code-investigator
generated: 9/19/2026, 5:08:33 PM
last updated: 9/19/2026, 8:08:42 PM
avoid.net — verified advice for a post-truth world