New Android Malware Discovered: Phones Exploited as Fraudulent Contactless Card Readers
A recently discovered Android malware variant is being utilized in tandem with a remote administration tool to extract payment card details from compromised devices, facilitating unauthorized transactions through legitimate point-of-sale systems.
The Malicious Activity Involves SpyNote and WindRelay
The malicious activity involves a combination of SpyNote and WindRelay, which enables threat actors to intercept and transmit card data in real time. SpyNote enables attackers to gain full control over a victim’s mobile device, granting access to sensitive functions and applications.
In a Documented Case, Cybercriminals Impersonated Banking Personnel
In a documented case, cybercriminals impersonated banking personnel to deceive victims into installing SpyNote, disguising it as a legitimate application. The attackers manipulated the app’s interface to include the victim’s name, enhancing its credibility.
Once Installed, SpyNote Was Used to Grant Administrative Privileges
Once installed, SpyNote was used to grant administrative privileges, allowing the threat actors to execute further actions without user interaction. Following the initial compromise, the attackers deployed WindRelay to exploit the device’s near-field communication (NFC) capabilities.
WindRelay Transforms Android Phones Into Unauthorized Contactless Card Readers
This malware transforms the Android phone into an unauthorized contactless card reader by capturing data exchanged between the victim’s payment card and the device. During a 13-minute interaction, the attacker instructed the victim to input their card’s PIN while tapping the card against the infected phone.
The Integration of SpyNote and WindRelay Represents a Novel Approach
The integration of SpyNote and WindRelay represents a novel approach to financial fraud, combining remote device control with physical card data interception. Traditional NFC relay attacks typically rely on social engineering to trick victims into installing malicious software and physically interacting with compromised devices.
Investigations by Cybersecurity Firm Group-IB Revealed Key Details
Investigations by cybersecurity firm Group-IB revealed that WindRelay samples were submitted to VirusTotal between November 2025 and July 2026. These samples communicated with four distinct command-and-control servers, indicating a coordinated campaign.
Targeting Appears Concentrated in Central European Regions
The targeting appears concentrated in Central European regions, with evidence suggesting that attackers impersonated local financial institutions. The languages used in the malicious applications and the nature of the scams align with operations in Czechia, Slovakia, and Slovenia.
The Malware’s Distribution Chain Includes SpyNote and Its Variants
The malware’s distribution chain includes SpyNote and its variants, such as SpyMax and CypherRAT, which have been active since at least 2021. These tools are designed to bypass security measures by exploiting user trust and system permissions.
Users Are Urged to Exercise Caution When Downloading Applications
Attackers often manipulate application labels and request sensitive permissions, such as access to NFC functionality, to execute their schemes. Users are urged to exercise caution when downloading applications from unverified sources, particularly those requesting unusual permissions.
Android Users Should Avoid Installing APK Files Outside of Official App Stores
Android users should avoid installing APK files outside of official app stores unless the publisher is explicitly trusted. Additionally, individuals receiving unsolicited calls claiming to represent their bank should terminate the call and contact the institution directly using verified contact details.
The Emergence of WindRelay Underscores Evolving Tactics of Cybercriminals
The emergence of WindRelay underscores the evolving tactics of cybercriminals in exploiting mobile device vulnerabilities. As NFC technology becomes more prevalent in financial transactions, the risk of similar attacks is expected to increase, necessitating heightened vigilance and robust security practices.
The integration of SpyNote and WindRelay represents a novel approach to financial fraud, combining remote device control with physical card data interception.
