LIVE NEWS
  • Trump dangles $500 ACA refund checks, but legal basis is unclear
  • Guest post: How extreme heat is ‘creeping’ from summer into autumn and spring
  • Musk threatens to sue filmmaker Alex Gibney for defamation : NPR
  • 25 Years After 9/11, What Makes a Good Counterterrorism Strategy?
  • Twenty-five years after 9/11, strategic shocks mustn’t cloud strategic thinking
  • Infectious diseases will seed new ground as the planet warms — here’s where they’ll spread
  • India crypto takedowns target 15 platforms
  • NFL’s Rams and 49ers head to Australia in international expansion
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»New Android malware relays bank cards to fraudsters while victims still hold them
Cybersecurity

New Android malware relays bank cards to fraudsters while victims still hold them

primereportsBy primereportsAugust 15, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access trojan, which gives attackers remote access to a victim’s device.

WindRelay Android malware

Attack chain overview (Source: Group-IB)

How the scam unfolds

The scam starts with a phone call, in which the fraudster claims to be from the victim’s bank and says there is a problem with their card. Guided step by step, the victim installs an app themselves.

That app is SpyNote, and it carries a detail meant to lower the victim’s guard. The app’s label shows the victim’s own name instead of a strange or generic one. Group-IB researchers found that SpyNote’s builder toolkit lets an operator customize the app’s label, name, and package for each target before deployment.

Once SpyNote has remote access, the fraudster installs a second app (WindRelay) on the device without further action from the victim. WindRelay uses NFC to communicate with the payment card and an internet connection to relay that exchange as it happens. It also requests access to the victim’s contacts and a system-inspection permission unusual for a third-party app.

“In one 13-minute phone call, the victim installed a RAT onto their own device — everything after that was performed by the fraudster. By the end of the call, the fraudster had taken out a loan in the victim’s name through remote access to the victim’s mobile app, and was streaming their card data to a fake merchant terminal,” Group-IB explained.

“Every transaction was approved using the PIN the victim had entered themselves. The victim stayed on a live call with the fraudster for the entire incident,” they added.

Card transactions began showing up on the victim’s account not long after the call ended.

Scale and targeting

Group-IB traced 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026, tied to campaigns targeting victims in Czechia, Slovakia, and Slovenia. Researchers also identified four command-and-control IP addresses associated with the NFC relay activity.

Several samples carried victim-specific names and interface text matching the language of the target country, showing how the apps were tailored for individual victims and locations.

“This case shows that modern fraud rarely relies on one technique. Here, the fraudster combined three capabilities in a single session — a live social engineering call, a personalized RAT for remote device control, and an NFC relay malware for physical cash-out,” Group-IB concluded.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleI Became a Mom at 19. at 35, I’m Figuring Out Who I Am Again.
Next Article September 15 and the bill: How XRP holders can turn the tide against the trend and earn $10,000 a day
primereports
  • Website

Related Posts

Cybersecurity

Microsoft says September updates fix mouse settings reset issues

September 10, 2026
Cybersecurity

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

September 9, 2026
Cybersecurity

Microsoft Plugs Nearly 1,000 Security Holes – Krebs on Security

September 9, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Threat of further violence looms after Mexican cartel rampage

February 25, 2026116 Views

‘Two-sided risk’ Medicare Advantage plans improve patient outcomes

February 24, 202673 Views

An $18bn settlement – and Zuckerberg barely blinked. The tech titans must be stripped of their power, and soon | Jonathan Freedland

August 28, 202626 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Crypto
  • Cybersecurity
  • Geopolitics
  • Artificial Intelligence
  • Popular Now
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Trump dangles $500 ACA refund checks, but legal basis is unclear
  • Guest post: How extreme heat is ‘creeping’ from summer into autumn and spring
  • Musk threatens to sue filmmaker Alex Gibney for defamation : NPR
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.