Fraudsters are using two Android malware tools together to steal payment-card data and take out loans in victims’ names during phone scams. Group-IB says attackers impersonate bank staff, trick victims into sideloading the SpyNote remote-access trojan (RAT) with Accessibility permissions, then install WindRelay to relay near-field communication (NFC) card data in real time after victims tap their bank card and enter a PIN. Samples seen from November 2025 to July 2026 suggest targeting in Czechia, Slovakia, and Slovenia.
Why it matters: This lets criminals turn a single phone call into immediate financial theft, including card fraud and unauthorized loans. Android users should avoid installing APKs from links or callers, never tap a payment card to a phone at a caller’s request, and banks and defenders should warn customers and staff about this vishing-led attack chain.
Bill Toulas
2026.08.12
100% relevant
This article establishes a distinct malware-and-fraud campaign centered on the WindRelay plus SpyNote attack chain, with concrete technical details, victim interaction steps, and regional targeting.
← Back to all stories