Android malware duo steals card data and takes loans in victims' names

A combination of two Android malware tools—WindRelay and the SpyNote remote administration tool—is being used to steal payment card data and fraudulently take out loans, cybersecurity firm Group-IB reports. In an investigated incident, an attacker impersonating a bank employee called a victim, instructed them to sideload the malicious SpyNote app, then remotely installed WindRelay and used the banking app to take out a loan in the victim's name.
The attacker instructed the victim to tap their payment card against the phone and enter their PIN. WindRelay converted the phone into a fraudulent contactless reader and relayed the card's near-field communication data—including transaction-specific authentication codes—to the attacker's device in real time, allowing fraudulent purchases at genuine payment terminals. The entire fraud occurred during a 13-minute call, Group-IB said.
Group-IB identified nearly two dozen WindRelay samples between November 2025 and July 2026 communicating with four command-and-control servers, with targeting appearing focused on Czechia, Slovakia and Slovenia, Bill Toulas reports for BleepingComputer.