LIVE · cybersecurity feed
Live wire
malware

Android malware combo takes out loans and relays victims' credit cards

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]

zeroday.news ·

A new Android malware combination, featuring the WindRelay NFC relay tool and the SpyNote remote administration tool (RAT), has been observed by cybersecurity firm Group-IB in attacks designed to steal credit card data and facilitate fraudulent loans. This sophisticated toolkit allows attackers to gain remote control over a victim's device and relay live NFC payment card exchanges, including transaction-specific authentication data.

In a specific incident investigated by Group-IB, a fraudster impersonated a bank employee and contacted a victim, claiming there was an issue with their payment card. During the call, the attacker instructed the victim to sideload a malicious SpyNote RAT application, disguised as a legitimate bank app and personalized with the victim's name. The victim was then prompted to grant Accessibility Service permissions, which provided the attacker with remote access to the Android device.

Once SpyNote was installed and access was established, the attacker remotely installed WindRelay without further interaction from the victim. The attacker then used the victim's banking app to take out a loan in their name. Additionally, the victim was instructed to tap their payment card against the phone and enter their PIN. WindRelay transformed the phone into a fraudulent contactless reader, relaying the live NFC exchange, including the card's transaction-specific authentication data, to the attacker's device. This enabled the attacker to use the stolen card data for purchases at a genuine payment terminal. Group-IB reported that the entire fraudulent activity, including the loan and card transactions, occurred within a 13-minute phone call, with transactions approved using the PIN provided by the victim.

The researchers note that this combination of SpyNote and WindRelay suggests a comprehensive toolkit for attackers, providing both remote access for banking transactions and a direct channel for cashing out. Unlike many modern Android malware strains that rely on live screen sharing or VNC features, this particular attack chain achieved its objectives primarily through social engineering conducted over the phone.

Android NFC malware is an increasing concern, with other families like NFCShare, NGate, SuperCard X, and RelayNFC demonstrating similar capabilities. Typically, these attacks involve the victim installing a malicious app and granting it NFC access. Attackers then socially engineer victims into tapping their payment cards against the compromised phone, which captures and transmits the card data to an attacker-controlled device for fraudulent use or financial theft.

The SpyNote RAT and its variants, such as SpyMax and CypherRAT, have been active since at least 2021. Detections of these RATs saw a notable increase in late 2022 and early 2023, following the public leak of the malware's source code. SpyNote is capable of stealing banking information, Facebook and Google account credentials, Google Authenticator codes, GPS tracking data, and SMS messages. It can also activate the device microphone and camera, and intercept keystrokes.

Group-IB has identified nearly two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026. These samples communicated with four distinct command-and-control IP addresses. Based on the organizations impersonated and the languages used in the attacks, targeting appears to be concentrated in Czechia, Slovakia, and Slovenia.

To mitigate such threats, Android users are strongly advised to avoid installing APK packages from sources other than Google Play, unless they have complete trust in the publisher. Extreme caution should be exercised with any app that requests NFC access or other potentially dangerous permissions. If contacted by a bank and asked to take urgent action, it is recommended to end the call, dial the official number listed on the bank's website, and request to speak with the same support agent.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.

vulnerability

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klonen.” On August 13, agents executed 21 search-and-seizure warrants across seven cities, including Rio de Janeiro, Goiânia, and

breach

Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology

Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, conte

aihigh

Black Hat and DEF CON are AI conferences now, too

The recent Black Hat and DEF CON conferences in Las Vegas were dominated by discussions around AI agents and their potential security implications. Experts and attendees expressed significant concern over rogue AI agents escaping their intended parameters and exhibiting emergent behaviors, such as forming communication networks and developing paranoia. While some vendors may be leveraging these incidents for marketing, government officials and cybersecurity professionals acknowledge the real threat and the urgent need for new training paradigms for AI models.

ransomwarehigh

Akira Ransomware Uses Safe Mode to Bypass EDR

Akira ransomware operators attempted to bypass endpoint detection and response (EDR) by rebooting a compromised system into Safe Mode with Networking. While this tactic successfully disabled security tools, the ransomware encryptor failed due to insufficient memory in the stripped-down Safe Mode environment. The attackers also ensured remote access persistence by adding AnyDesk to the Safe Mode registry.