Skip to main content
AVOID.NET

Manic (Android Banking Trojan / Crypto-Wallet-Targeting Malware)

avoid.net/manic-android-banking-trojan-crypto-wallet-targeting-malware1/100·80% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

Manic is an active Android malware family, publicly disclosed by the Dutch mobile-threat intelligence firm ThreatFabric on August 20, 2026 and separately covered by Kaspersky, that combines banking-trojan credential theft with spyware and full device-takeover capabilities. It monitors 169 Android app package IDs — including banks, payment apps, cryptocurrency wallets and exchanges, government eID services, authenticator apps, messengers, browsers and email clients — and is notable for an invisible-overlay keystroke capture technique paired with Accessibility-service replay, plus a novel offline Wi-Fi/Bluetooth mesh exfiltration mechanism that relays stolen data through other nearby infected phones even when the source device has no internet access. Manic is not a company or product to be trusted but an active criminal threat; it is indexed here as a risk entity so that crypto holders on Android can recognize and avoid it.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Manic (Android Banking Trojan / Crypto-Wallet-Targeting Malware)?

Timeline(8 events)

February 2026

First infrastructure associated with the Manic campaign (domain registration under a fabricated persona) is registered, marking the earliest traced activity of the malware family.

ThreatFabric / BleepingComputer

March 2026

Development and production services supporting the Manic campaign begin to come online, per ThreatFabric's infrastructure timeline (dated to late March/April 2026).

ThreatFabric

May 2026

The first retained malware wrapper and implant appear, using a booking-app lure for initial distribution.

ThreatFabric / The Hacker News

July 2026

Following a development hiatus, a reworked Manic build is deployed with stronger anti-analysis protections, in-memory DEX loading, and new lock-screen secret theft capability; a new operator panel/API is also introduced.

ThreatFabric / The Hacker News

20 August 2026

ThreatFabric publicly discloses the Manic malware family in a technical blog post; the disclosure is simultaneously covered by The Hacker News and BleepingComputer.

The Hacker News

20 August 2026

BleepingComputer publishes coverage of Manic's Wi-Fi/Bluetooth mesh exfiltration technique, including Google's statement that no apps containing the malware were found on Google Play.

BleepingComputer

August 2026

Kaspersky publishes its own analysis of Manic on the Kaspersky Daily blog, corroborating ThreatFabric's findings on offline data exfiltration and credential theft.

Kaspersky Daily

31 August 2026

eSecurity Planet publishes further coverage summarizing Manic's bank-account-draining capability and offline mesh exfiltration.

eSecurity Planet
Provenance & Audit Trail
6 Wayback Archives

6 of 7 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 9/19/2026, 5:08:33 PM

last updated: 9/19/2026, 8:08:42 PM

avoid.net — verified advice for a post-truth world