Android Malware Relays NFC Cards, Takes Out Loans
WindRelay, a new Android NFC relay malware, is deployed alongside SpyNote RAT to steal live card data and take out fraudulent loans in victims' names.
New Android malware combo observed in the wild. Two tools, two fraud vectors, one campaign.
What’s confirmed: A previously undocumented Android NFC relay malware, tracked as WindRelay, is being deployed alongside SpyNote — a well-documented Android remote administration tool — to steal live payment card data and take out loans in victims’ names. BleepingComputer reported the campaign on August 12, 2026.
How the combination works: NFC relay attacks intercept contactless payment signals from a victim’s device and relay them to attacker-controlled infrastructure in real time, enabling card-present fraud at POS terminals the victim never touched. WindRelay is the NFC relay component. SpyNote handles the broader access layer — keylogging, screen capture, SMS interception, camera and microphone access — providing the additional account credentials needed to complete fraudulent loan applications using the victim’s compromised identity.
Confidence: Confirmed exploitation reported. SpyNote is a long-documented RAT with public analysis going back years; its capabilities are established. WindRelay is newly identified — details on initial distribution vector not yet confirmed in reporting reviewed.
Why this matters: NFC relay malware isn’t new as a concept, but pairing it with a full-capability RAT that can also harvest identity documents and account credentials extends fraud well beyond card skimming. Taking out loans in a victim’s name requires more than card data — the RAT access fills that gap.
What to do:
- Android users: review recently installed apps for unusual permissions (NFC access, accessibility services, device administrator rights). Remove anything unverified.
- Disable NFC when not in use. It is off by default on most devices; confirm yours matches.
- If you suspect compromise: contact your bank immediately, place a fraud alert with credit bureaus, and do a factory reset before restoring from backup.
- Mobile threat teams: SpyNote IOCs are available in prior public analysis; WindRelay IOCs should be emerging from the BleepingComputer report and associated research.
Source: BleepingComputer, August 12, 2026.
Found this useful? Share it.


