LIVE · cybersecurity feed
Live wire
malware

New Android malware lets criminals use your bank card in real time

Social engineering, a Remote Access Trojan (RAT), and NFC relay malware walk up to an ATM. It's no joke. Together, they can empty your bank account.

zeroday.news ·

Cybersecurity researchers at Group-IB have identified a new Android malware family, dubbed WindRelay, designed to facilitate real-time contactless payment card fraud. This malware operates by capturing live NFC (Near Field Communication) data from a victim's physical bank card and relaying it instantly to an attacker-controlled device, which can then be used for fraudulent purchases or ATM withdrawals.

The attack typically begins with a sophisticated social engineering tactic, often involving a lengthy phone call where attackers impersonate a bank representative. In one observed instance, a 13-minute call persuaded a victim to install an Android application branded with the bank's name. This initial application was a remote access Trojan (RAT) known as SpyNote, which granted the attackers full remote control over the victim's smartphone.

Once SpyNote was installed, the attackers silently deployed WindRelay onto the device. They then remotely accessed the victim's legitimate banking application, initiating a loan in the victim's name. During this process, the victim was instructed to tap their physical payment card against their phone and enter its PIN. This action allowed WindRelay to intercept the dynamic, one-time cryptographic data generated by the contactless payment card and transmit it in real time to the criminals.

The critical aspect of this attack is the real-time relaying capability. Unlike static NFC signals, modern contactless payment cards generate unique, transaction-specific codes (cryptograms or tokens) that cannot be reused. WindRelay's ability to relay this data instantaneously is essential for bypassing these security measures. The coordinated phone call serves not only as the initial lure but also as a control channel, enabling attackers to guide the victim through the installation, card tap, and PIN entry at precise moments.

This method falls under a broader category of NFC relay fraud, sometimes referred to as "ghost tapping," and shares similarities with previously identified malware families like NGate and SuperCard X. However, the current campaign is notable for its integration with the SpyNote RAT, which provides the attackers with comprehensive remote control over the victim's device and facilitates the stealthy deployment of the relay malware.

To protect against such threats, individuals are advised to exercise extreme caution regarding unsolicited calls or messages, particularly those demanding urgent action. Banks will not request customers to install applications from unofficial sources, links in text messages, or browser downloads to secure their cards. Users should avoid "sideloading" apps from outside official app stores like Google Play and be wary of unexpected requests for Accessibility or device-control permissions.

It is also recommended to verify any suspicious requests by contacting financial institutions directly using official phone numbers, rather than numbers provided in potentially fraudulent communications. Never disclose personal details to unexpected callers or change banking details at their instruction. Employing an up-to-date, real-time anti-malware solution on mobile devices can help detect and block such threats. Malwarebytes for Android, for example, identifies SpyNote and WindRelay as Android/Trojan.NGate.ACRBCF9BBC3C1 and Android/Trojan.NGate.ACR2401245FC5, respectively.

malwarefinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.