Android malware combo takes out loans and relays victims' credit cards
WindRelay is an Android NFC relay malware used in combination with the SpyNote remote administration tool (RAT) to steal live payment card data and commit financial fraud. Attackers socially engineer victims to install SpyNote disguised as a legitimate app, granting remote access to their device. Subsequently, WindRelay is installed to relay NFC card data in real time, enabling attackers to perform fraudulent transactions including taking out loans and making purchases using the victim's card. The attack relies heavily on social engineering and occurs rapidly, often within minutes. Targeting appears focused on Czechia, Slovakia, and Slovenia. Users are advised to avoid sideloading apps from untrusted sources and be cautious with apps requesting NFC or accessibility permissions.
AI Analysis
Technical Summary
The threat involves a combination of two Android malware families: WindRelay, an NFC relay malware, and SpyNote, a remote administration tool. Attackers impersonate bank employees to trick victims into installing SpyNote with Accessibility Service permissions, granting full remote control. Using this access, attackers install WindRelay, which turns the victim's phone into a fraudulent contactless reader that relays live NFC payment card data, including transaction-specific authentication data, to the attacker. This enables real-time fraudulent transactions such as loans and purchases using the victim's card and PIN. The entire attack can be completed within a short phone call. Group-IB researchers identified multiple WindRelay samples communicating with attacker-controlled servers, with targeting focused on Central European countries. The attack chain relies on social engineering rather than exploiting technical vulnerabilities in Android itself.
Potential Impact
The combined use of SpyNote RAT and WindRelay malware allows attackers to gain remote control of victims' Android devices and steal live NFC payment card data. This enables attackers to perform unauthorized financial transactions, including taking out loans in the victim's name and making purchases at genuine payment terminals using relayed card data and PINs. Victims suffer financial loss and potential credit damage. The attack bypasses typical Android security controls by relying on social engineering to obtain permissions and install malware. The rapid execution of the attack (within approximately 13 minutes) increases the risk of successful fraud before victims can respond.
Mitigation Recommendations
There is no vendor patch or official fix for this malware combination as it relies on social engineering and user interaction. Users should avoid sideloading APKs from untrusted sources and be cautious about granting Accessibility Service and NFC permissions to apps. If contacted by a purported bank representative requesting urgent action, users should terminate the call and independently verify by calling the bank using official contact information. Android users should only install apps from trusted sources such as Google Play. Awareness training on social engineering tactics can help reduce risk. No specific technical remediation is available to remove or block this malware beyond standard mobile security best practices.
Affected Countries
Czechia, Slovakia, Slovenia
Android malware combo takes out loans and relays victims' credit cards
Description
WindRelay is an Android NFC relay malware used in combination with the SpyNote remote administration tool (RAT) to steal live payment card data and commit financial fraud. Attackers socially engineer victims to install SpyNote disguised as a legitimate app, granting remote access to their device. Subsequently, WindRelay is installed to relay NFC card data in real time, enabling attackers to perform fraudulent transactions including taking out loans and making purchases using the victim's card. The attack relies heavily on social engineering and occurs rapidly, often within minutes. Targeting appears focused on Czechia, Slovakia, and Slovenia. Users are advised to avoid sideloading apps from untrusted sources and be cautious with apps requesting NFC or accessibility permissions.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat involves a combination of two Android malware families: WindRelay, an NFC relay malware, and SpyNote, a remote administration tool. Attackers impersonate bank employees to trick victims into installing SpyNote with Accessibility Service permissions, granting full remote control. Using this access, attackers install WindRelay, which turns the victim's phone into a fraudulent contactless reader that relays live NFC payment card data, including transaction-specific authentication data, to the attacker. This enables real-time fraudulent transactions such as loans and purchases using the victim's card and PIN. The entire attack can be completed within a short phone call. Group-IB researchers identified multiple WindRelay samples communicating with attacker-controlled servers, with targeting focused on Central European countries. The attack chain relies on social engineering rather than exploiting technical vulnerabilities in Android itself.
Potential Impact
The combined use of SpyNote RAT and WindRelay malware allows attackers to gain remote control of victims' Android devices and steal live NFC payment card data. This enables attackers to perform unauthorized financial transactions, including taking out loans in the victim's name and making purchases at genuine payment terminals using relayed card data and PINs. Victims suffer financial loss and potential credit damage. The attack bypasses typical Android security controls by relying on social engineering to obtain permissions and install malware. The rapid execution of the attack (within approximately 13 minutes) increases the risk of successful fraud before victims can respond.
Defensive Guidance
There is no vendor patch or official fix for this malware combination as it relies on social engineering and user interaction. Users should avoid sideloading APKs from untrusted sources and be cautious about granting Accessibility Service and NFC permissions to apps. If contacted by a purported bank representative requesting urgent action, users should terminate the call and independently verify by calling the bank using official contact information. Android users should only install apps from trusted sources such as Google Play. Awareness training on social engineering tactics can help reduce risk. No specific technical remediation is available to remove or block this malware beyond standard mobile security best practices.
Technical Details
- Classification
- {"confidence":0.85,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/","fetched":true,"fetchedAt":"2026-08-12T22:41:16.552Z","wordCount":938}
Threat ID: 6a7cf68cbf8831d53944368f
Added to database: 08/12/2026, 22:41:16 UTC
Last enriched: 08/12/2026, 22:41:25 UTC
Last updated: 08/13/2026, 01:58:55 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.