Android malware combo takes out loans and relays victims’ credit cards

Android Malware Combo Takes Out Loans and Relays Victims’ Credit Cards in Real-Time

A disturbing combination of malware has been used by attackers to steal card data from unsuspecting Android users, taking out loans and making unauthorized purchases using their credit cards. The malicious duo, consisting of the SpyNote remote administration tool (RAT) and WindRelay NFC relay malware, has been identified by cybersecurity firm Group-IB in a recent investigation.

The attack begins with social engineering, where a fraudster impersonates a bank employee and convinces the victim to sideload the SpyNote RAT disguised as a legitimate app. Once installed, the attacker gains remote access to the device through SpyNote and installs WindRelay without further interaction with the victim. The victim is then instructed to tap their payment card on the phone and enter their PIN, allowing WindRelay to relay the live NFC exchange, including the card’s transaction-specific authentication data, to the attacker’s device.

This malicious combo has been used in a 13-minute phone call, where transactions were approved using the PIN provided by the victim. Group-IB highlights that this combination may indicate a toolkit that provides both access to the victim’s device for banking transactions and a direct cash-out channel. What’s particularly concerning is that this malware mix enables attackers to commit fraud solely through social engineering over the phone, without relying on live screen sharing or VNC features.

The use of NFC relay malware is a growing problem in Android cybersecurity, with notable examples including NFCShare, NGate, SuperCard X, and RelayNFC. In a typical attack, the victim installs a malicious app and grants it access to NFC, allowing the attacker to capture available data from the contactless payment card. This data can then be used for unauthorized transactions or other financial theft.

The SpyNote RAT has been circulating since at least 2021, with an increase in detections recorded in late 2022 and early 2023 following the leak of its source code. The malware can steal bank data, Facebook and Google account credentials, Google Authenticator codes, GPS tracking, and SMS texts, as well as activate the device microphone and camera.

Group-IB has identified almost two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026 that communicated with four command-and-control IP addresses. The targeting appears focused on Czechia, Slovakia, and Slovenia, based on the organizations impersonated and languages used.

To avoid falling victim to this type of attack, Android users should exercise caution when receiving calls from their bank or other institutions. If you receive a call asking for urgent action, terminate the call immediately and dial the number listed on the organization’s official website to verify the request. Additionally, be wary of apps that request NFC access or other dangerous permissions outside of Google Play.

As the cyber threat landscape continues to evolve, it’s essential for users to stay informed and take proactive measures to protect their devices and personal data. By being vigilant and cautious in our online interactions, we can reduce the risk of falling prey to these sophisticated attacks.


Source: Bleeping Computer — 2026-08-12