Android NFC malware combo takes out loans and relays victims' credit cards
New WindRelay malware works with SpyNote RAT to steal card data and approve loans during a 13-minute call.
Fraudsters posed as bank employees on a phone call and, within 13 minutes, sideloaded a remote access trojan, installed a novel NFC relay malware, used the victim's banking app to take out a loan, and walked away with live credit card data. The incident, investigated by cybersecurity firm Group-IB, highlights a growing trend of Android malware that turns smartphones into fake contactless readers.
A Deceptive Call, a Sideloaded RAT
According to Group-IB, the attacker called the victim pretending to be a bank employee, claiming there was a problem with the victim's payment card. During the call, the fraudster instructed the victim to sideload the SpyNote RAT, a known Android remote administration tool, disguised as a legitimate app.
The victim was then social-engineered into granting Accessibility Service permissions, which gave the attacker remote control over the device. To make the malicious app seem authentic, the attacker personalized its app label with the victim's name, a tactic that adds credibility during the social engineering process.
WindRelay: A Real-Time NFC Relay
After gaining access through SpyNote, the attacker installed WindRelay without any further interaction from the victim. This malware turns the phone into a fraudulent contactless reader, capable of communicating with a physical payment card via near-field communication (NFC).
The victim was instructed to tap their payment card on the phone and enter their PIN. WindRelay then relayed the live NFC exchange, including the card's transaction-specific authentication data, to the attacker's device in real time. This allowed the attacker to use the card data for purchases at a genuine payment terminal, effectively performing a relay attack.
A 13-Minute Loan and a Cash-Out Channel
Group-IB reports that the entire attack occurred during a 13-minute phone call, and transactions were approved using the PIN provided by the victim. Once the attacker had remote access, they used the banking app on the victim's device to take out a loan in the victim's name, adding financial damage beyond the direct card fraud.
This combination of SpyNote and WindRelay suggests a toolkit that provides both access to the victim's device for banking transactions and a direct cash-out channel, according to the researchers. In contrast to many modern Android malware strains that rely on live screen sharing and VNC features, this mix enabled fraud solely through social engineering over the phone, making it a distinct and dangerous approach.
Android NFC Malware on the Rise
The growing problem of Android NFC malware is underscored by the emergence of families like NFCShare, NGate, SuperCard X, and RelayNFC, as reported by BleepingComputer.
In a typical attack, the victim installs a malicious app and grants it NFC access. The attacker then uses social engineering to trick the victim into tapping their payment card against the compromised phone. The phone's NFC interface communicates with the contactless payment card, captures available data, and transmits it over the internet to an attacker-controlled device.
Depending on the data obtained, the attacker may be able to use it for fraudulent transactions or other financial theft, including ATM cash withdrawals. This is not a theoretical risk; it is actively being exploited in the wild.
SpyNote's Evolution and Leaked Source
The SpyNote RAT, along with variants like SpyMax and CypherRAT, has been circulating since at least 2021. Detections of SpyNote saw an increase in detections in late 2022 and early 2023, following the leak of the malware's source code.
SpyNote is a powerful trojan capable of stealing bank data, Facebook and Google account credentials, Google Authenticator codes, GPS tracking, and SMS texts. It can also activate the device's microphone and camera, and intercept keystrokes. The availability of its source code has likely lowered the barrier for less skilled attackers to deploy this malware in campaigns.
Targeted Regions and Command-and-Control
Group-IB identified almost two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026 that communicated with four command-and-control IP addresses. The targeting appears focused on Czechia, Slovakia, and Slovenia, based on the organizations impersonated and the languages used in the attack lures.
This geographic focus suggests that the attackers have localized their social engineering scripts and may be operating within or near these regions. The use of specific languages and impersonated organizations adds a layer of sophistication that increases the likelihood of success.
Defense: Caution with APKs and Calls
Android users are advised to avoid APK packages outside Google Play unless they know and trust the publisher. Be especially cautious with apps that request NFC access or other dangerous permissions, as these are often abused by malware.
When receiving a call from your bank and asked to take urgent action, it is advisable to terminate the call, dial the number listed on the organization's official website, and ask to connect with the same support agent. This simple step can prevent falling victim to such social engineering scams.
Why This Matters for Android Users
The WindRelay campaign shows that cybercriminals are refining their tactics to combine remote access with real-time NFC relay, enabling both loan fraud and card fraud from a single 13-minute phone call. The fact that the attacker could take out a loan in the victim's name and use the card data for purchases at a genuine terminal underscores the financial devastation that can follow. This suggests that users must treat unsolicited calls from banks with extreme skepticism, and that the combination of social engineering and NFC relay techniques could become more common.
Sources
- BleepingComputer Original source
- growing problem Also reporting
- NFCShare Also reporting
- NGate Also reporting
- SuperCard X Also reporting
- increase in detections Also reporting
- leak of the malware’s source code Also reporting
Continue Reading
Plug and Pwn attacks exploit Windows PnP for SYSTEM
Researchers show fake USB devices can trigger Windows to install vulnerable vendor software, granting SYSTEM privileges.
Lazarus zero-day fools Google in Dream Job wave
New Lazarus campaign abuses Windows zero-day and fake job lures to breach defense firms, fooling Google's filters.
Fake Hires: The Identity Gap in Onboarding
State and FBI warnings highlight how fake remote workers bypass hiring controls to gain network access.