New Manic Android Malware Exploits Bluetooth to Steal Data from Nearby Devices

www.news4hackers.com-new-manic-android-malware-exploits-bluetooth-to-steal-data-from-nearby-devices-new-manic-android-malware-exploits-bluetooth-to-steal-data-from-nearby-devices

ThreatFabric identifies new Android malware Manic leveraging peer-to-peer data relays and accessibility services for surveillance and financial fraud.

Introduction

New Android malware named Manic employs a unique data exfiltration method leveraging nearby infected devices. The threat has been active since at least February and combines surveillance, financial fraud, and remote control functionalities.

Key Features of Manic Malware

Surveillance and Financial Fraud

Manic targets 169 applications including banking, government/eID, payment, cryptocurrency wallet, messaging, and authentication tools, with a primary focus on Ukrainian users. Security firm ThreatFabric identified the malware’s use of transparent overlays on numeric keypads within legitimate apps to capture user input.

Targeted Applications

These overlays exploit Android Accessibility services to replicate taps while allowing normal app operation. Once granted Accessibility and notification access permissions, the malware can intercept lock screen credentials, monitor SMS and notifications, collect files and location data, and enable remote control via WebRTC.

Attack Chain and Infrastructure

Initial Delivery

Manic’s attack chain involves initial delivery through a wrapper that expands infrastructure over time. Researchers observed updated wrappers in May with enhanced anti-analysis measures and in-memory DEX loading by July.

Anti-Analysis Measures

The malware employs an alternative data exfiltration method when C2 servers are unreachable, encrypting data and transmitting it via Wi-Fi Direct or Bluetooth to nearby compromised devices. This mechanism prioritizes established Wi-Fi Direct connections before scanning Bluetooth and BLE peers for internet access.

Data Exfiltration Mechanism

Peer-to-Peer Relay

If needed, data can traverse up to four relay hops. This allows offline devices to exfiltrate data when within range of other infected devices. ThreatFabric notes the malware targets applications across Central and Western Europe, the U.K., and Russia, with heightened focus on Ukrainian banking and government/eID services.

Security Implications

The malware’s ability to operate without constant C2 connectivity makes it particularly resilient. Technical analysis reveals its sophisticated use of Android’s accessibility framework and peer-to-peer data relaying capabilities. Security professionals advise vigilance against unknown app installations and regular system audits to detect potential compromises.

ThreatFabric notes the malware targets applications across Central and Western Europe, the U.K., and Russia, with heightened focus on Ukrainian banking and government/eID services. While the exact infection vector remains unclear, the malware’s infrastructure has expanded since late May. Attackers gain access to systems through compromised devices, with only 37% of their actions blocked once credentials are obtained.

Conclusion

The threat highlights evolving tactics in mobile malware development, emphasizing the need for advanced detection mechanisms. The malware’s unique peer-to-peer exfiltration method and reliance on Android accessibility services underscore the importance of proactive security measures and user awareness.


Blog Image

About Author

en_USEnglish