This Android malware steals banking credentials even without an internet connection | Kaspersky official blog

Refract AI Intelligence Digest

BLUF

Manic Trojan bypasses traditional network monitoring to exfiltrate financial data from offline Android devices via peer-to-peer relay.

NEWS

Kaspersky Security Blog reports the Manic Trojan compromises Android devices to harvest passwords and banking details. The malware operates offline by storing credentials locally and relaying them through a network of other infected phones. This method allows data exfiltration even when the victim device lacks direct internet access.

Why I Care

This capability undermines network-based detection systems and compromises two-factor authentication via SMS interception. Mobile banking users and enterprises with BYOD policies face increased risk of financial theft and unauthorized account access.

Next Steps

End users must scan devices with updated security software and uninstall suspicious apps immediately. IT administrators should restrict app installation sources to official stores and review network logs for anomalous peer-to-peer traffic today.

How the Manic Trojan steals passwords, banking credentials and SMS codes, takes control of Android phones, and relays stolen information through other infected devices.
Back to Blog Listing

Source: Kaspersky Security Blog ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.