The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 10:20 am AEST · 13 August 2026

Android malware duo steals card data and takes loans in victims' names

Android malware duo steals card data and takes loans in victims' names
Photograph: BleepingComputer

A combination of two Android malware tools—WindRelay and the SpyNote remote administration tool—is being used to steal payment card data and fraudulently take out loans, cybersecurity firm Group-IB reports. In an investigated incident, an attacker impersonating a bank employee called a victim, instructed them to sideload the malicious SpyNote app, then remotely installed WindRelay and used the banking app to take out a loan in the victim's name.

The attacker instructed the victim to tap their payment card against the phone and enter their PIN. WindRelay converted the phone into a fraudulent contactless reader and relayed the card's near-field communication data—including transaction-specific authentication codes—to the attacker's device in real time, allowing fraudulent purchases at genuine payment terminals. The entire fraud occurred during a 13-minute call, Group-IB said.

Group-IB identified nearly two dozen WindRelay samples between November 2025 and July 2026 communicating with four command-and-control servers, with targeting appearing focused on Czechia, Slovakia and Slovenia, Bill Toulas reports for BleepingComputer.

Android malware combo takes out loans and relays victims' credit cards A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. bleepingcomputer.com
cybersecurityfraud-scamsmalwareandroid-malwarepayment-fraud

Follow the live coverage →

Android malware duo steals card data and takes loans in victims' names | The Financial Register Inward Money