Find notable cyber news and cases, enriched with sources, timelines, and signals.

Manic Android malware activity with offline relay exfiltration

Malware Activity
First reported
Last updated
Happening score
H score 27
1 unique sources, 1 articles

Summary

Hide ▲

The Manic Android malware is active across multiple European countries, with Ukraine as its main focus, and its fallback exfiltration path can keep data moving even when a victim device cannot reach C2. The malware combines spyware, banking fraud, and remote control features, widening the risk of credential theft and device takeover. It also targets at least 169 apps across banking, government/eID, payment, crypto wallet, messaging, and 2FA categories.

Related Happenings

ToxicPanda 2.0 Android malware expands fraud capabilities

Malware Activity
H score29 First: 20.08.2026 13:38 Last: 20.08.2026 13:38 Sources 1

About this happening: The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...

ToxicPanda 2.0 Android banking trojan expansion

Malware Activity
H score28 First: 20.08.2026 13:00 Last: 20.08.2026 13:00 Sources 1

About this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...

RedWing Android spyware rented through Telegram

Malware Activity
H score21 First: 08.07.2026 18:30 Last: 08.07.2026 18:30 Sources 1

About this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...

RedWing Android bank-fraud malware rental service

Malware Activity
H score21 First: 07.07.2026 20:10 Last: 07.07.2026 20:10 Sources 1

About this happening: The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...

Rokarolla Android banking trojan activity

Malware Activity
H score26 First: 16.06.2026 16:15 Last: 16.06.2026 16:15 Sources 1

About this happening: The Rokarolla Android banking trojan is expanding phone-level control on infected devices, letting attackers steal credentials, intercept authentication codes, and hide fr...

Timeline

  1. 20.08.2026 13:02 2 articles · 1h ago

    Manic Android malware activity with offline relay exfiltration

    Initial Disclosure

    The Manic Android malware first surfaced as a multifunction tool aimed at banking and government/eID apps, with Ukraine as the main focus. Early activity already showed a payload-delivery wrapper and expanding supporting infrastructure.

    Show sources