Android malware combo takes out loans and relays victims’ credit cards

A New Android Malware Combo Steals Credit Cards and Takes Out Loans via Phone Calls

Cyber attackers have devised a sophisticated scheme to steal credit card information and take out loans using a combination of malware tools on Android devices. The malicious operation involves phone calls, social engineering, and the exploitation of Accessibility Services permissions to gain remote access to victims’ phones.

In an incident investigated by Group-IB, a threat actor impersonated a bank employee and contacted a victim, claiming there was a problem with their payment card. The attacker instructed the victim to sideload a malicious app called SpyNote, which is a Remote Administration Tool (RAT), disguised as a legitimate application. Once installed, the RAT granted the attacker remote access to the device. To further deceive the victim, the attacker personalized the malware label with the victim’s name.

After gaining control of the device through SpyNote, the attacker installed another piece of malware called WindRelay, which uses the phone’s Near-Field Communication (NFC) interface to capture and relay credit card data in real-time. The victim was instructed to tap their payment card on the phone and enter their PIN, allowing the attacker to use the stolen data for purchases at a genuine payment terminal.

This malicious operation is particularly concerning because it demonstrates how attackers can commit fraud solely through social engineering over the phone, without relying on live screen sharing or VNC features. The combination of SpyNote and WindRelay may indicate a toolkit that provides both access to the victim’s device for banking transactions and a direct cash-out channel.

Android NFC malware has been on the rise, with notable examples including NFCShare, NGate, SuperCard X, and RelayNFC. These threats typically involve installing malicious apps that grant access to NFC, which are then used to capture credit card data and transmit it over the internet to an attacker-controlled device.

The SpyNote RAT has been circulating since at least 2021, with variants such as SpyMax and CypherRAT gaining traction in recent years. The malware can steal bank data, Facebook and Google account credentials, GPS tracking information, and SMS texts, among other sensitive data.

To prevent falling victim to this type of attack, Android users should exercise caution when receiving calls from their banks or financial institutions. If asked to take urgent action, it’s best to terminate the call, dial the number listed on the organization’s official website, and ask to connect with the same support agent. Avoid installing APK packages outside Google Play, and be wary of apps that request NFC access or other sensitive permissions.

By being vigilant and taking these precautions, Android users can significantly reduce their risk of falling victim to this type of attack.


Source: Bleeping Computer — 2026-08-12