New Manic Android Malware Exploits Bluetooth to Steal Data from Nearby Devices
ThreatFabric identifies new Android malware Manic leveraging peer-to-peer data relays and accessibility services for surveillance and financial fraud.
Introduction
New Android malware named Manic employs a unique data exfiltration method leveraging nearby infected devices. The threat has been active since at least February and combines surveillance, financial fraud, and remote control functionalities.
Key Features of Manic Malware
Surveillance and Financial Fraud
Manic targets 169 applications including banking, government/eID, payment, cryptocurrency wallet, messaging, and authentication tools, with a primary focus on Ukrainian users. Security firm ThreatFabric identified the malware’s use of transparent overlays on numeric keypads within legitimate apps to capture user input.
Targeted Applications
These overlays exploit Android Accessibility services to replicate taps while allowing normal app operation. Once granted Accessibility and notification access permissions, the malware can intercept lock screen credentials, monitor SMS and notifications, collect files and location data, and enable remote control via WebRTC.
Attack Chain and Infrastructure
Initial Delivery
Manic’s attack chain involves initial delivery through a wrapper that expands infrastructure over time. Researchers observed updated wrappers in May with enhanced anti-analysis measures and in-memory DEX loading by July.
Anti-Analysis Measures
The malware employs an alternative data exfiltration method when C2 servers are unreachable, encrypting data and transmitting it via Wi-Fi Direct or Bluetooth to nearby compromised devices. This mechanism prioritizes established Wi-Fi Direct connections before scanning Bluetooth and BLE peers for internet access.
Data Exfiltration Mechanism
Peer-to-Peer Relay
If needed, data can traverse up to four relay hops. This allows offline devices to exfiltrate data when within range of other infected devices. ThreatFabric notes the malware targets applications across Central and Western Europe, the U.K., and Russia, with heightened focus on Ukrainian banking and government/eID services.
Security Implications
The malware’s ability to operate without constant C2 connectivity makes it particularly resilient. Technical analysis reveals its sophisticated use of Android’s accessibility framework and peer-to-peer data relaying capabilities. Security professionals advise vigilance against unknown app installations and regular system audits to detect potential compromises.
ThreatFabric notes the malware targets applications across Central and Western Europe, the U.K., and Russia, with heightened focus on Ukrainian banking and government/eID services. While the exact infection vector remains unclear, the malware’s infrastructure has expanded since late May. Attackers gain access to systems through compromised devices, with only 37% of their actions blocked once credentials are obtained.
Conclusion
The threat highlights evolving tactics in mobile malware development, emphasizing the need for advanced detection mechanisms. The malware’s unique peer-to-peer exfiltration method and reliance on Android accessibility services underscore the importance of proactive security measures and user awareness.
