<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards-zkhg3khej" -->

---
title: Android malware combo takes out loans and relays...
description: A newly identified Android NFC relay malware called WindRelay is being deployed alongside the SpyNote remote access trojan to commit real-time financial fraud....
canonical: https://daily.dev/posts/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards-zkhg3khej
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Android malware combo takes out loans and relays victims&#x27; credit cards | daily.dev
og:description: A newly identified Android NFC relay malware called WindRelay is being deployed alongside the SpyNote remote access trojan to commit real-time financial fraud....
og:url: https://daily.dev/posts/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards-zkhg3khej
og:image: https://api.daily.dev/og/posts/ZKhG3khEJ.png
og:image:alt: Android malware combo takes out loans and relays victims&#x27; credit cards
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Android malware combo takes out loans and relays victims' credit cards

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 0 upvotes · 0 comments

## Summary

A newly identified Android NFC relay malware called WindRelay is being deployed alongside the SpyNote remote access trojan to commit real-time financial fraud. In an incident documented by Group-IB, attackers impersonated a bank employee, convinced a victim to sideload SpyNote disguised as a legitimate app, gained Accessibility Service permissions for remote device control, then installed WindRelay without further victim interaction to take out a loan in the victim's name. The victim was also tricked into tapping their payment card and entering their PIN, letting WindRelay relay the live NFC exchange to the attacker's device for use at a real payment terminal. The whole scam took 13 minutes over a phone call. Group-IB found nearly two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026, targeting mainly Czechia, Slovakia, and Slovenia. This adds to a growing family of Android NFC relay malware including NFCShare, NGate, SuperCard X, and RelayNFC.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards>

## Questions this post answers

### What is WindRelay Android malware and how does it work with SpyNote?

WindRelay is an Android NFC relay malware that turns an infected phone into a fraudulent contactless card reader, capturing live NFC data including transaction-specific authentication codes and relaying it to an attacker's device for use at a real payment terminal. It is deployed alongside the SpyNote remote access trojan, which attackers use to gain Accessibility Service permissions and install WindRelay without further victim interaction, then take out loans through banking apps.

_Security teams tracking new mobile fraud techniques like NFC relay attacks can follow the latest coverage on daily.dev._

### Which countries are being targeted by the WindRelay NFC malware?

Targeting appears focused on Czechia, Slovakia, and Slovenia, based on the organizations impersonated and the languages used in the fraudulent calls. Group-IB identified almost two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026, communicating with four command-and-control IP addresses.

_Anyone monitoring regional malware campaigns can keep an eye on emerging NFC fraud trends via daily.dev._

### How can I protect myself from Android NFC relay scams involving fake bank calls?

Avoid sideloading APK packages from outside Google Play unless the publisher is known and trusted, and be cautious of apps requesting NFC access or other dangerous permissions. If someone claiming to be from a bank calls asking for urgent action, hang up and call back using the number listed on the bank's official website, then ask to be connected to the same agent.

_Developers building anti-fraud defenses can stay current on social engineering tactics targeting mobile users through daily.dev._

## Similar posts on daily.dev

- [RelayNFC Targets Brazil](https://daily.dev/posts/relaynfc-targets-brazil-mti8kp6z0) · Cyble · 1 upvotes · 0 comments
- [NFC tap-to-pay gets tapped by hackers](https://daily.dev/posts/nfc-tap-to-pay-gets-tapped-by-hackers-qihxjff0m) · CSO Online · 0 upvotes · 0 comments
- [Brazil Hit by Banking Trojan Spread via WhatsApp Worm and RelayNFC NFC Relay Fraud](https://daily.dev/posts/brazil-hit-by-banking-trojan-spread-via-whatsapp-worm-and-relaynfc-nfc-relay-fraud-lt4ojamt8) · The Hacker News · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#android](https://daily.dev/tags/android), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards-zkhg3khej)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Android malware combo takes out loans and relays victims' credit cards","url":"https://daily.dev/posts/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards-zkhg3khej","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards-zkhg3khej"},"datePublished":"2026-08-12T22:25:23.705Z","dateModified":"2026-08-12T22:25:49.338Z","description":"A newly identified Android NFC relay malware called WindRelay is being deployed alongside the SpyNote remote access trojan to commit real-time financial fraud....","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9699d0e1bf3e7688074e501da3200288?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9699d0e1bf3e7688074e501da3200288?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards-zkhg3khej","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,android,malware","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Android malware combo takes out loans and relays victims' credit cards"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards-zkhg3khej#faq","mainEntity":[{"@type":"Question","name":"What is WindRelay Android malware and how does it work with SpyNote?","acceptedAnswer":{"@type":"Answer","text":"WindRelay is an Android NFC relay malware that turns an infected phone into a fraudulent contactless card reader, capturing live NFC data including transaction-specific authentication codes and relaying it to an attacker's device for use at a real payment terminal. It is deployed alongside the SpyNote remote access trojan, which attackers use to gain Accessibility Service permissions and install WindRelay without further victim interaction, then take out loans through banking apps. Security teams tracking new mobile fraud techniques like NFC relay attacks can follow the latest coverage on daily.dev."}},{"@type":"Question","name":"Which countries are being targeted by the WindRelay NFC malware?","acceptedAnswer":{"@type":"Answer","text":"Targeting appears focused on Czechia, Slovakia, and Slovenia, based on the organizations impersonated and the languages used in the fraudulent calls. Group-IB identified almost two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026, communicating with four command-and-control IP addresses. Anyone monitoring regional malware campaigns can keep an eye on emerging NFC fraud trends via daily.dev."}},{"@type":"Question","name":"How can I protect myself from Android NFC relay scams involving fake bank calls?","acceptedAnswer":{"@type":"Answer","text":"Avoid sideloading APK packages from outside Google Play unless the publisher is known and trusted, and be cautious of apps requesting NFC access or other dangerous permissions. If someone claiming to be from a bank calls asking for urgent action, hang up and call back using the number listed on the bank's official website, then ask to be connected to the same agent. Developers building anti-fraud defenses can stay current on social engineering tactics targeting mobile users through daily.dev."}}]}
```

