Startup Bets

Android malware steals card details in real time

 ·  By Flavia Pembridge
Android malware steals card details in real time - android malware
Android malware steals card details in real time

Cybersecurity researchers have identified a new malware strain targeting Android users in Central Europe. The attack steals payment card data while the physical card remains in the user’s possession.

How the scam unfolds over a single phone call

The fraud starts with a call from someone pretending to be a bank employee. The caller claims there is a problem with the victim’s card and instructs them to install an app to fix it. That app is SpyNote, a remote access trojan that grants attackers full control of the device.

SpyNote’s design mimics legitimate software. It displays the victim’s name instead of a generic label, a feature enabled by a customization toolkit that lets attackers personalize the app for each target before sending it. After installation, the fraudster silently installs a second app, WindRelay, without the user’s knowledge.

WindRelay captures payment card data. It uses NFC to interact with the victim’s card and sends the information to a remote server in real time. The malware also requests access to contacts and a system-inspection permission rarely needed by legitimate apps.

One documented case lasted 13 minutes. By the end of the call, the attacker had taken out a loan in the victim’s name and was transmitting card data to a fake merchant terminal. Transactions appeared on the victim’s account soon after, all approved using the PIN they had entered.

Tailored attacks across three countries

Researchers found 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026. The campaigns focused on Czechia, Slovakia, and Slovenia, with some samples featuring interface text in the local language and victim-specific names.

Related: ESET unveils AI security for autonomous agents

The malware’s command-and-control infrastructure included four IP addresses tied to the NFC relay activity. The customization indicates attackers are investing effort to make each attack seem more believable, lowering the chance victims will realize something is wrong.

The scheme relies heavily on social engineering. The fraudster keeps the victim on the call throughout, preventing them from noticing unauthorized activity until fraudulent transactions appear. The mix of live interaction, remote device control, and real-time data theft makes detection difficult.

This attack demonstrates a rising threat: physical possession of a card no longer guarantees security. The malware doesn’t clone the card—it only needs to relay its data long enough to complete a transaction. Banks and payment processors may need to update fraud detection to address relay-based theft, which can bypass traditional safeguards like transaction limits or location checks.

Group-IB, which discovered the malware, explained that modern fraud rarely depends on a single method. Here, attackers combined social engineering, remote access, and NFC relaying to increase success rates. The layered approach shows how criminals adapt to security improvements, using multiple techniques to evade defenses.

Security measures must evolve to counter these threats.

Leave a Comment

Your email address will not be published.