Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Android malware combo takes out loans and relays victims’ credit cards

    August 12, 2026

    “City-Forum” data-theft attacks target Salesforce, ServiceNow portals

    August 12, 2026

    UK Cyber Resilience: Closing the Execution Gap

    August 12, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Android malware combo takes out loans and relays victims’ credit cards
    News

    Android malware combo takes out loans and relays victims’ credit cards

    adminBy adminAugust 12, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Android malware combo takes out loans and relays victims' credit cards

    A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time.

    In an incident investigated by the cybersecurity company Group-IB, a fraudster impersonated a bank employee and called the victim under the pretense of a problem with their payment card.

    During the call, the threat actor instructed the victim to sideload the SpyNote RAT disguised as a legitimate app and grant it Accessibility Service permissions, giving the attacker remote access to the Android device.

    image

    To add credibility, the attacker personalized the malicious app label with the victim’s name.

    Builder creates victim-specific SpyNote APKs
    Builder creates victim-specific SpyNote APKs
    Source: Group-IB

    After gaining remote access to the device through SpyNote, the attacker installed WindRelay without further interaction with the victim and used the banking app to take out a loan in the victim’s name.


    Additionally, the victim was instructed to tap their payment card on the phone and enter their PIN. WindRelay turned the phone into a fraudulent contactless reader and relayed the live NFC (near-field communication) exchange, including the card’s transaction-specific authentication data, to the attacker’s device.


    This allowed the attacker to use the card data for purchases at a genuine payment terminal.


    Group-IB says that the entire activity occurred in a 13-minute phone call, and transactions were approved using the PIN provided by the victim.


    Attack chain overview
    Attack chain overview
    Source: Group-IB

    The researchers highlight that the combination of SpyNote and WindRelay may indicate a toolkit that provides both access to the victim’s device for banking transactions and a direct cash-out channel.

    Also, in contrast to most modern Android malware with live screen sharing and VNC features, this malware mix enabled the attackers to commit fraud solely through social engineering over the phone.

    Android NFC malware is a growing problem, as shown by malware families such as NFCShare, NGate, SuperCard X, and RelayNFC.

    In a typical attack, the victim installs a malicious app and grants it access to NFC. The attacker then uses social engineering to trick the victim into tapping their payment card against the compromised phone.

    The phone uses its NFC interface to communicate with a contactless payment card and capture available data, which it then transmits over the internet to an attacker-controlled device.

    Depending on the data obtained and the technique used, the attacker may be able to use it for fraudulent transactions or other financial theft, including ATM cash withdrawals.

    The SpyNote RAT and variants such as SpyMax and CypherRAT have been circulating since at least 2021 and recorded an increase in detections in late 2022 and early 2023, following the leak of the malware’s source code.

    The malware can steal bank data, Facebook and Google account credentials, Google Authenticator codes, GPS tracking, and SMS texts. It can also activate the device microphone and camera, and generic intercept keystrokes.

    Group-IB has identified almost two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026 that communicated with four command-and-control IP addresses.

    According to the researchers, targeting appears focused on Czechia, Slovakia, and Slovenia, based on the organizations impersonated and the languages used.

    Unless they know and trust the publisher, Android users are advised to avoid APK packages outside Google Play, and to be very careful with apps that request NFC access or other dangerous permissions.

    When receiving a call from your bank and asked to take urgent action, it is advisable to terminate the call, dial the number listed on the organization’s official website, and ask to connect with the same support agent.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article“City-Forum” data-theft attacks target Salesforce, ServiceNow portals
    admin
    • Website

    Related Posts

    News

    “City-Forum” data-theft attacks target Salesforce, ServiceNow portals

    August 12, 2026
    News

    UK Cyber Resilience: Closing the Execution Gap

    August 12, 2026
    News

    Here’s the Manual for ICE’s Electric Shock Gloves

    August 12, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views
    Our Picks

    Android malware combo takes out loans and relays victims’ credit cards

    August 12, 2026

    “City-Forum” data-theft attacks target Salesforce, ServiceNow portals

    August 12, 2026

    UK Cyber Resilience: Closing the Execution Gap

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.