A mobile security firm has discovered a new type of malware named Manic, which has been active since February 2026. This malware merges two distinct types of malicious software: banking Trojans, which steal financial information, and spyware, which secretly gathers personal data. Manic targets 169 different apps, including banks and cryptocurrency wallets, by monitoring user activity through messaging apps and two-factor authentication systems. While Ukraine is the primary target, French banks have also been identified as potential victims. The malware often disguises itself as legitimate applications, similar to how fake websites mimic popular software to trick users. One of the most concerning features of Manic is its ability to transfer stolen data without requiring an active internet connection. If an infected smartphone can't reach a command server, it encrypts the data and stores it temporarily. It then looks for another nearby infected device through Wi-Fi Direct or Bluetooth. This data is passed along using up to four relays, allowing a disconnected device to share sensitive information with another nearby device that still has internet access. This method is stealthy because it mimics regular device interactions like file sharing or synchronization over Bluetooth and local Wi-Fi networks. The malware also uses Android’s accessibility service, a feature originally intended to help people with disabilities navigate their phones. Manic abuses this feature to record keystrokes by placing a transparent overlay on the numeric keypad of banking apps. This overlay captures each touch and replays the gesture using the accessibility service, allowing the app to function normally without showing any fake interface. As a result, users are unaware they are being monitored and continue typing on their real keyboard. Manic collects a wide range of sensitive information, including PIN codes, SMS verification codes, recovery phrases, passwords, notifications, contacts, and location data. It can also remotely control the phone screen, making messaging apps especially vulnerable. This is particularly concerning because a recent vulnerability in WhatsApp allowed attackers to access photos and lock phones remotely. Although the exact method of infection is unclear, it is believed that a disguised installer delivered the final payload. Google has confirmed that no Manic-infected apps are available on the Play Store, and its security system, Play Protect, blocks known versions of the malware. Users are advised to avoid downloading APK files from unknown sources, limit accessibility permissions to only necessary apps, and regularly use Play Protect scans. Additionally, SMS-based authentication remains vulnerable to scams like SIM swapping, highlighting the need for more secure verification methods.