A newly discovered Android malware strain called Manic targets financial institutions and government infrastructure across Eastern Europe and beyond through a sophisticated network propagation method that works even when devices remain offline.

Security researchers identified Manic actively compromising Ukrainian banks, government services, identity platforms, and messaging applications. The threat also strikes Russian and European financial institutions, fintech companies, cryptocurrency exchanges, and military communications infrastructure. The malware operates as a hybrid banking trojan and spyware, combining data theft capabilities with financial fraud functionality.

Manic's most distinctive characteristic is its ability to exfiltrate data from offline Android devices through nearby infected phones. The malware establishes a proximity-based relay network, allowing compromised devices to communicate data to each other without requiring internet connectivity. This approach creates significant operational advantages for attackers. Victims using offline-first security strategies discover their devices remain vulnerable. The relay mechanism permits data extraction even when targets disable cellular or WiFi functionality.

The malware exhibits dual functionality typical of sophisticated mobile threats. As banking malware, Manic intercepts financial transactions, captures credentials, and redirects user authentication flows. As spyware, it harvests contacts, call logs, SMS messages, location data, and application usage patterns. This combination makes Manic valuable for both financial fraud and intelligence gathering operations.

The geographic targeting pattern suggests attribution to a threat group operating from or aligned with Eastern European interests. Ukrainian institutions face heightened exposure, indicating potential state-sponsored or state-aligned activity. The inclusion of Russian financial targets alongside European institutions suggests operators prioritize geopolitical and financial objectives rather than pure cybercriminal profit.

Distribution vectors remain under investigation, though Android malware typically spreads through compromised application stores, phishing campaigns, or watering hole attacks. Users installing applications from unofficial sources face elevated risk. The malware may also propagate through credential theft enabling unauthorized access to legitimate accounts.

Organizations should implement application allowlisting on Android devices to prevent unauthorized software execution. Endpoint detection and response solutions capable of identifying suspicious inter-process communication and unusual network behavior provide additional protection. Users should avoid sideloading applications and maintain updated device software.

Financial institutions should enhance transaction verification procedures and implement behavioral analytics to detect compromised sessions. Government agencies should conduct network segmentation to isolate sensitive systems from potentially compromised endpoints. Military communications infrastructure warrants immediate security reviews given explicit targeting.

The offline propagation capability represents a notable escalation in Android threat sophistication. Traditional endpoint protection assumes network-isolated devices remain secure. Manic demonstrates that proximity-based propagation creates new attack surfaces. This technical approach may inspire additional threat groups to adopt similar distribution mechanisms.

Device users in targeted regions should exercise extreme caution with application installations and avoid using personal devices for sensitive financial or government transactions where possible. Organizations handling critical infrastructure should enforce mandatory multifactor authentication and implement continuous monitoring of financial and government systems for unauthorized access indicators.