New Android Malware WindRelay Steals Card Data and Takes Out Loans

Photo: BleepingComputer
Quick answer
Cybercriminals have combined the Android malware WindRelay with the SpyNote trojan to steal banking card data and fraudulently take out loans on victims' devices.
Group-IB researchers have uncovered a new fraud scheme combining the Android malware WindRelay and the SpyNote trojan. Attackers call victims, posing as bank employees, and trick them into installing a malicious app under the pretext of resolving card-related issues. To boost credibility, the APK filename is personalized using the victim's name.
After installing SpyNote and obtaining Accessibility Service permissions, attackers gain full remote control over the device. They then install WindRelay, which turns the smartphone into a fake NFC reader. Victims are instructed to tap their card against the phone and enter their PIN—at which point the malware intercepts card data and transmits it to the attackers. Simultaneously, fraudsters take out loans through the victim's banking app. The entire attack takes about 13 minutes.
Experts note that the combination of SpyNote and WindRelay enables attackers not only to steal card data but also to immediately withdraw funds by taking out loans. Unlike other Android trojans, this scheme requires no complex technical actions—just social engineering and a brief phone call. The primary targets are users in the Czech Republic, Slovakia, and Slovenia, though similar threats may spread to other regions.
Group-IB identified nearly two dozen WindRelay samples uploaded to VirusTotal between November 2025 and July 2026. The SpyNote trojan and its variants (SpyMax, CypherRAT) have been actively distributed since 2021, especially after its source code leaked in late 2022. To stay protected, experts recommend installing apps only from Google Play, avoiding dangerous permissions, and verifying the authenticity of calls from banks.
Common questions
- How does the WindRelay malware work?
- WindRelay turns an infected Android device into a fake NFC reader, intercepting banking card data when the card is tapped against the phone. The stolen data is transmitted to attackers in real time for immediate misuse.
- What are the capabilities of the SpyNote trojan?
- SpyNote is a Remote Administration Tool (RAT) that allows attackers to remotely control the device, steal banking credentials, Google and Facebook* accounts, Google Authenticator codes, SMS messages, and even activate the microphone and camera.
- How can users protect themselves from such attacks?
- Avoid installing APK files from untrusted sources, refrain from granting dangerous permissions (such as NFC or Accessibility Service) to unknown apps, and verify suspicious calls from alleged bank representatives by contacting the official number.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml