HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Manic Android Malware Harvests Credentials via Accessibility Service, Exfiltrates Data Offline

Manic, a new Android malware family, leverages the Accessibility service to keylog lock‑screen PINs, 2FA codes, and passwords, exfiltrating the data via Bluetooth even when the device is offline. The threat underscores the need for robust mobile access‑control policies and continuous audit evidence for SOC 2 compliance.

LiveThreat™ Intelligence · 📅 August 21, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Manic Android Malware Harvests Credentials via Accessibility Service, Exfiltrates Data Offline

What Happened — ThreatFabric’s Mobile Threat Intelligence team identified “Manic,” an Android malware family that combines banking fraud and spyware. It uses the Accessibility service as a UI keylogger, captures lock‑screen PINs, 2FA codes, passwords, and other sensitive text, and can exfiltrate the data even when the device is offline via a Bluetooth relay.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how unchecked app permissions can bypass SOC 2 CC6 (Logical Access) controls, creating gaps in credential protection.
  • Highlights the need for continuous monitoring of mobile device configurations as audit evidence of “least‑privilege” enforcement.
  • Reinforces the importance of Security Awareness Training to reduce user‑initiated installation of malicious apps.

Who Is Affected — Financial services (banks, fintech, crypto exchanges), government identity services, and any organization whose employees use Android devices for sensitive transactions.

Recommended Actions

  • Enforce strict Mobile Device Management (MDM) policies that block third‑party Accessibility and notification‑access requests unless explicitly approved.
  • Map the Accessibility‑service misuse to SOC 2 CC6 controls, collect permission‑grant logs as evidence, and integrate them into your continuous‑compliance dashboard.
  • Conduct targeted security‑awareness sessions on the risks of granting high‑privilege permissions to unknown apps.

Technical Notes — Manic monitors 169 Android apps, employs in‑memory DEX loading, anti‑analysis checks, and a “lock‑secret phishing” UI overlay to harvest device PINs. Exfiltration occurs via a Bluetooth relay, allowing data theft even when the phone lacks network connectivity. Source: SecurityAffairs

📰 Original Source
https://securityaffairs.com/197570/malware/manic-the-android-malware-that-exfiltrates-data-even-when-the-phone-is-offline.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →