A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.

"Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud capabilities with broader surveillance and device-control features," ThreatFabric said in a technical report shared with The Hacker News.

The malware, besides targeting sensitive applications and enabling extensive device takeover, introduces a novel Wi‑Fi mesh technique that makes it possible for the infected devices to relay data through nearby compromised devices with internet access. It's distributed via phishing sites and dropper apps impersonating utilities.

The Dutch security company said the malware family's activity dates back to February 2026, when the first domain was registered with a fabricated persona. Active development efforts ensued not long after, with the first wrapper using a booking app lure and the implant appearing by the end of May.

But in an interesting twist, these efforts were abandoned from late June to mid-July, while signs of a second deployment emerged around July 13. The newer iteration of the wrapper and the implant have been found to incorporate stronger anti-analysis checks and the ability to phishing lock screen secrets. A corresponding panel and API subsequently went live between July 24 and 28.