Cybersecurity companies this week shared information about new and updated banking trojans targeting users worldwide.
These types of malware can enable their operators to phish credentials, steal sensitive user data, and remotely control compromised devices.
Manic
ThreatFabric has detailed Manic, described as an Android malware that combines banking trojan and spyware capabilities.
The malware has mainly been used against Ukraine, including banks, government services, and messaging applications. However, it has also been observed targeting Russian and European financial institutions, global cryptocurrency and fintech services, and military-focused messaging apps.
Distributed via malicious websites and droppers, the malware enables attackers to log keystrokes, display phishing screens, and remotely control the compromised phone for banking and cryptocurrency fraud.
In addition, Manic includes spyware capabilities such as notification monitoring, location tracking, file harvesting, and remote device surveillance.
“A particularly distinctive capability is its offline mesh relay, which allows collected data to move through nearby infected devices over Wi-Fi Direct or Bluetooth when direct C2 access is unavailable,” ThreatFabric noted.