A newly analyzed Android malware family called Manic is targeting users across multiple European countries and has been active since at least February, according to BleepingComputer, citing research from mobile security firm ThreatFabric. The report says Ukraine is the primary focus, particularly for banking and government/eID applications, though targeted apps are also used across Central and Western Europe, the U.K., and Russia. The technical finding that stands out is Manic’s fallback exfiltration path. BleepingComputer reports that when an infected device cannot reach the malware’s command-and-control server, Manic can send encrypted stolen data through nearby compromised devices using Wi-Fi Direct, Bluetooth, or Bluetooth Low Energy. ThreatFabric said the malware first tries an existing Wi-Fi Direct peer, then checks Bluetooth and BLE peers for internet connectivity. That relay model matters because it can give operators a path out of an otherwise offline infected phone, provided another compromised device is within wireless range. BleepingComputer reports that Manic can also use multi-hop routes, with newly queued items configured for a maximum of four relay hops by default. The provided material does not say how often this fallback path has been observed in real-world theft, only that the capability exists in the malware analyzed by ThreatFabric. Manic’s broader feature set combines spyware, banking fraud, and remote-control functions. After obtaining Android Accessibility and notification access permissions, the malware can capture a victim’s lock PIN or password, intercept notifications and SMS messages, collect files and location data, monitor the screen, and give operators remote control through WebRTC sessions, according to BleepingComputer’s summary of the research. ThreatFabric also found that Manic uses transparent overlays on numeric keypads inside legitimate applications. BleepingComputer reports that this lets the malware record victims’ taps and reproduce them through Android Accessibility while the legitimate application continues to work normally. The malware also categorizes captured information by type, including lock-screen input, possible recovery phrases, four- to six-digit SMS codes, passwords, longer messages, email logins, and ordinary text. The target list is broad. BleepingComputer says Manic targets at least 169 apps spanning banking, government/eID, payment, crypto wallet, messaging, and authenticator or two-factor authentication categories. The report identifies Ukraine as the main focus, while also noting global fintech and cryptocurrency services in the target set. The initial infection vector remains unknown. ThreatFabric observed a wrapper delivering the main payload in late May, followed by infrastructure expansion in later months, according to BleepingComputer. In July, researchers saw an updated wrapper with stronger anti-analysis checks and in-memory DEX loading, along with a new panel and application programming interface. For defenders and Android users, the practical guidance remains basic but relevant: avoid APKs from obscure or unofficial sources, deny Accessibility permissions unless a trusted app clearly needs them, and run Google Play Protect scans. The report is a reminder that post-compromise behavior can be more complex than initial infection metrics suggest, especially when malware can use nearby infected devices as part of its data path. Who benefits: The apparent beneficiaries are Manic’s operators, who gain a fallback route for data exfiltration when a compromised device cannot directly reach command-and-control infrastructure. The mechanism may also help them extract data from devices that are temporarily offline but near another infected handset. Who's exposed: Android users targeted through the listed app categories are exposed, especially users in Ukraine, which BleepingComputer says is the primary focus. Users who install APKs from unofficial sources or grant Accessibility permissions to untrusted apps face elevated risk based on the behavior described.