Android Malware Combo Takes Out Loans and Relays Victims' Credit Cards
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time.
Intelligence analysis by Llama

A threat actor impersonated a bank employee and called the victim under the pretense of a problem with their payment card. The victim was instructed to sideload the SpyNote RAT disguised as a legitimate app and grant it Accessibility Service permissions, giving the attacker remote access to the Android device.
Imagine someone calls you from your bank and asks you to install a special app on your phone. They tell you it's for a problem with your payment card. But really, it's a way for them to steal your card data and use it to make fake purchases. This is called a social engineering attack, and it's a way for bad people to trick you into doing something that helps them.
Analysis
WindRelay and SpyNote: A Deadly Duo
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time. This combination of malware may indicate a toolkit that provides both access to the victim's device for banking transactions and a direct cash-out channel.
The researchers highlight that the entire activity occurred in a 13-minute phone call, and transactions were approved using the PIN provided by the victim. The attack chain overview shows how the attackers used social engineering to trick the victim into tapping their payment card against the compromised phone.
Android NFC Malware: A Growing Problem
Android NFC malware is a growing problem, as shown by malware families such as NFCShare, NGate, SuperCard X, and RelayNFC. In a typical attack, the victim installs a malicious app and grants it access to NFC. The attacker then uses social engineering to trick the victim into tapping their payment card against the compromised phone.
Prevention is Key
Unless they know and trust the publisher, Android users are advised to avoid APK packages outside Google Play, and to be very careful with apps that request NFC access or other dangerous permissions. When receiving a call from your bank and asked to take urgent action, it is advisable to terminate the call, dial the number listed on the organization's official website, and ask to connect with the same support agent.
Key points
- A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time.
- The attackers used social engineering to trick the victim into tapping their payment card against the compromised phone.
- Android users are advised to avoid APK packages outside Google Play and to be careful with apps that request NFC access or other dangerous permissions.
If this development plays out positively, it could lead to increased awareness and education among Android users about the dangers of NFC malware and the importance of being cautious when receiving calls from unknown numbers.
The realistic downside risks or failure modes of this development include the potential for widespread adoption of WindRelay and SpyNote, leading to a significant increase in NFC malware attacks and financial theft.


