
ThreatFabric released a new report, and this one is focusing on Android malware called ‘Manic’. This thing is a hybrid between a banking trojan and spyware made to watch the user of an infected device.
Manic is a new Android Trojan that watches 169 banking apps & more
Manic watches 169 package IDs, in total. That goes for technical identifiers of individual apps. That list includes banks, payment services, buy now pay later, remittances, crypto exchanges, wallets, messengers, browsers, email clients, government eID apps, and authenticator apps.
As you can see, its scope is vast. ThreatFabric says that it managed to track its first infrastructure back to February 2026. A far stronger build landed in July, though, with more powerful anti-analysis checks.
The campaign is aimed mainly at Ukraine, but it’s not limited to that country. The list also includes banks in Germany, Poland, the Czech Republic, Slovakia, Austria, France, Spain, Estonia, Lithuania, the Netherlands, and the UK. It is also watching several eID apps in those countries.
It paints a copied bank interface over the real app
This banking trojan paints a copied bank interface over the real app. It looks very close to the original. Manic finds a numeric keypad inside a target app, then it lays a transparent surface exactly over those keys. As you tap, Manic records the positioning, then briefly switches off its own touch interpretation, and replays the taps at the same spots through Android’s accessibility settings. That way, the PIN ends up with the attacker.
A second function of Manic is called autoEnterPin, at least by ThreatFabric. It works at the lock screen and tries to enter a previously captured PIN or pattern. The accessibility services double as a keylogger.
ThreatFabric lists tech.intel.dialer.updater, org.honor.secure.helper, org.lenovo.storage.processor, dev.huawei.media.helper, tech.apple.dialer.scheduler and io.motorola.secure.executor as identifiers for this malware. It does not show in the app menu, as the latest update allows it to be hidden. You can find these identifiers in the app list in the settings.
Its functionality depends on two permissions
Everything this malware can do depends on two permissions: accessibility services and notification access. You can open the accessibility settings on your Android phone and check the listed services there. The same goes for notification access.
Manic also attempts to disable Google Play Protect, so you should also check the Google Play Store. It is unclear how many devices are infected at this point.
The post New Android Trojan “Manic” Combines Banking Fraud With Spyware appeared first on Android Headlines.
​Â