HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Manic Android Malware Harvests Data from Offline Phones via Nearby Infected Devices

A new Android banking‑spyware hybrid, Manic, can exfiltrate credentials and messaging data from phones that are not online by leveraging nearby infected devices. The campaign targets banks, government identity services, and fintech firms, underscoring the need for robust mobile access controls and continuous compliance evidence.

LiveThreat™ Intelligence · 📅 August 20, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Manic Android Malware Harvests Data from Offline Phones via Nearby Infected Devices

What Happened — Researchers have identified a new Android banking‑spyware hybrid, codenamed Manic, that can steal data from phones that are not actively connected to the internet. The malware spreads through Bluetooth/nearby‑device pairing and then uses an infected “relay” device to exfiltrate credentials, banking tokens, and messaging data.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a gap in mobile device access controls – SOC 2 CC6.1 (Logical Access) expects documented safeguards for all endpoints, including offline devices.
  • Provides a concrete example of why continuous evidence collection (e.g., MDM logs, Bluetooth activity) is essential to prove control effectiveness during an audit.
  • Highlights the need for security‑awareness training that covers proximity‑based threats, a requirement for SOC 2 CC1.2 (Control Environment) and CC7.1 (System Operations).

Who Is Affected – Financial services (Ukrainian banks, European fintech, crypto platforms), government identity services, and any organization whose staff use Android devices for sensitive communications.

Recommended Actions

  • Map the incident to SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) – update your mobile‑device policy to require encryption, MDM enrollment, and Bluetooth restrictions.
  • Deploy continuous monitoring of Android endpoints (MDM logs, BLE activity) and retain logs as audit evidence.
  • Conduct targeted security‑awareness sessions on proximity‑based malware and safe Bluetooth practices.
  • Validate that third‑party mobile‑app vendors follow the same controls and obtain evidence for vendor‑risk assessments.

Source: The Hacker News

Technical Notes – Manic combines classic banking‑trojan code with spyware capabilities; it propagates via Android’s “Nearby Share” feature, leveraging Bluetooth Low Energy (BLE) to pair with offline phones. Exfiltrated data includes banking credentials, OTP tokens, and messaging app logs. No public CVE is associated, as the threat exploits legitimate OS features rather than a software flaw.

📰 Original Source
https://thehackernews.com/2026/08/manic-android-malware-exfiltrates-data.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →