bleeping-computer · Crawled Aug 13, 2026

Android malware combo takes out loans and relays victims' credit cards

6 IoCs 2 Malware
Read original article ↗

AI Summary

A new Android malware campaign combines WindRelay, an NFC relay tool, with the SpyNote remote administration trojan to enable real-time financial fraud. Attackers socially engineer victims by impersonating bank employees, tricking them into sideloading a malicious APK that grants Accessibility Services, enabling remote device control. The attackers then install WindRelay to capture NFC payment card data and PINs during live phone calls, allowing them to conduct fraudulent transactions or take out loans in the victim's name. The attack chain was executed entirely over a 13-minute call, highlighting a shift toward real-time, voice-mediated social engineering without requiring persistent malware access.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 6 extracted

Type Value Detail
IP 91[.]108[.]20[.]15 Details →
IP 91[.]108[.]20[.]16 Details →
IP 91[.]108[.]20[.]17 Details →
IP 91[.]108[.]20[.]18 Details →
Filename WindRelay.apk Details →
Filename SpyNote.apk Details →

MITRE ATT&CK TTPs 8 techniques