The combination of Android malware takes out loans and forwards victims’ credit cards

The combination of Android malware takes out loans and forwards victims' credit cards

A new Android NFC relay malware called WindRelay is being used in conjunction with the SpyNote Remote Administration Tool (RAT) to steal card data and send it to attackers in real time.

In an incident investigated by cyber security company Group-IB, a fraudster posed as a bank employee and called the victim on the pretext that there was a problem with their payment card.

During the conversation, the threat actor instructs the victim to load the SpyNote RAT disguised as a legitimate application and grant it service accessibility permissions, giving the attacker remote access to the Android device.

image

To add credibility, the attacker customizes the malicious app’s label with the victim’s name.

Builder creates SpyNote APK for specific victims
Builder creates SpyNote APK for specific victims
Source: Group-IB

After gaining remote access to the device via SpyNote, the attacker installs WindRelay without further interaction with the victim and uses the banking application to withdraw a loan in the victim’s name.


Additionally, the victim is instructed to tap their payment card on the phone and enter their PIN. WindRelay turned the phone into a rogue contactless reader and relayed a live NFC (near field communication) exchange, including transaction-specific card authentication data, to the attacker’s device.


This allowed the attacker to use the card data to make purchases at a real payment terminal.


Group-IB says the entire activity took place in a 13-minute phone call and transactions were approved using the PIN provided by the victim.


Overview of the attack chain
Overview of the attack chain
Source: Group-IB

The researchers emphasize that the combination of SpyNote and WindRelay can display a toolset that provides both access to the victim’s device for banking transactions and a direct withdrawal channel.

Also, unlike most modern Android malware with live screen sharing and VNC features, this combination of malware allows attackers to commit fraud solely through phone social engineering.

Android NFC malware is a growing problem, as evidenced by malware families such as NFCShare, NGate, SuperCard X, and RelayNFC.

In a typical attack, the victim installs a malicious app and grants it access to NFC. The attacker then uses social engineering to trick the victim into tapping their payment card against the compromised phone.

The phone uses its NFC interface to communicate with a contactless payment card and capture the available data, which it then transmits over the Internet to an attacker-controlled device.

Depending on the data obtained and the technique used, an attacker may be able to use it for fraudulent transactions or other financial theft, including withdrawing cash from an ATM.

The SpyNote RAT and variants such as SpyMax and CypherRAT have been circulating since at least 2021 and saw an increase in detections in late 2022 and early 2023, after the malware’s source code was leaked.

Malware can steal bank details, Facebook and Google account credentials, Google Authenticator codes, GPS tracking and SMS texts. It can also activate the device’s microphone and camera and intercept common keystrokes.

Group-IB identified nearly two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026 that communicated with four command-and-control IP addresses.

According to the researchers, the targeting appears to be focused on the Czech Republic, Slovakia and Slovenia based on the organizations being represented and the languages ​​used.

Unless they know and trust the publisher, Android users are advised to avoid APK packages outside of Google Play and to be very careful with apps that require access to NFC or other unsafe permissions.

When you receive a call from your bank and ask for urgent action, it is recommended that you end the call, dial the number listed on the official website of the organization and ask to be contacted by the same support agent.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *