This Android Malware Duo Is Draining Bank Accounts in Real Time

·
Listen to this article~6 min

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote RAT to steal live card data and send it to attackers in real time. Learn how to protect yourself.

You probably think your credit card is safe as long as it's sitting in your wallet. But what if I told you there's a new Android attack that can read your card's data from across the room and drain your bank account before you even notice? Security researchers just uncovered a nasty combination of malware that's doing exactly that. It's called WindRelay, and it works alongside a remote administration tool (RAT) known as SpyNote. Together, they're pulling off something that sounds like it belongs in a spy movie: stealing live card data and relaying it to attackers in real time. Let me break down what's happening, why it matters to you, and what you can do to protect yourself. ### How the Attack Actually Works The key here is NFC, or Near Field Communication. That's the tech that lets you tap your phone to pay at a store. It's convenient, sure, but it also opens a door for attackers. Here's the flow: WindRelay malware gets installed on your Android phone, often through a malicious app or a phishing link. Once it's in, it can read NFC data from nearby cards. That means if you're standing in line at a coffee shop with your credit card in your pocket, the malware on your phone could potentially pick up that card's data. But it doesn't stop there. The malware doesn't just steal the data and hold it. It relays it straight to the attacker in real time. Meanwhile, SpyNote gives the attacker full remote control over your device. They can see your screen, log your keystrokes, and even take out loans in your name. ### Why This Is Different From Other Threats You've probably heard about card skimmers at gas stations or ATM machines. Those are physical devices that capture your card's magnetic stripe data. This is different because it's entirely digital and can happen without you ever touching a compromised machine. What makes this combo particularly dangerous is the speed. The attackers aren't waiting to collect a batch of stolen cards and sell them on the dark web. They're using the data immediately to open lines of credit, transfer money, and make purchases. By the time you check your bank statement, the damage is already done. ### Who's at Risk? If you're an Android user, you're in the crosshairs. This attack specifically targets Android devices because the malware needs to be installed on the phone itself. It's especially concerning for people who use mobile payment apps or who keep their credit cards in phone cases with NFC capabilities. The researchers who found this didn't specify a particular region, but given how these campaigns usually work, it's safe to assume anyone with an Android phone could be targeted. And with the rise of contactless payments in the United States, the potential victim pool is huge. ### How to Protect Yourself Here's the good news: you can take steps to shut this down before it starts. Let's walk through some practical moves. - **Turn off NFC when you don't need it.** This is the simplest fix. If you're not tapping to pay, keep NFC disabled. It's a tiny switch in your settings, and it kills the attack vector completely. - **Be picky about the apps you install.** Stick to the Google Play Store and even then, check the developer and read reviews. Sideloading apps from random websites is how most people get infected. - **Don't click links in text messages or emails.** Even if they look legitimate, verify the sender before you tap anything. Phishing is the number one way these malware strains get onto phones. - **Keep your phone updated.** Android security patches fix vulnerabilities that attackers exploit. If you're running an old version, you're leaving the door open. - **Use a separate card for mobile payments.** If you have a card with a low limit or a prepaid card, use that for tap-to-pay. That way, even if your data is stolen, the attacker can't do much with it. ### What to Do If You Think You're Compromised If you notice unusual activity on your bank account or your phone is acting strange, act fast. Here's your checklist: 1. Contact your bank immediately and freeze your accounts. 2. Run a security scan on your phone using a reputable antivirus app. 3. Check your installed apps and uninstall anything you don't recognize. 4. Reset your phone to factory settings if you suspect a deep infection. 5. Change all your passwords from a different, trusted device. ### The Bigger Picture This isn't just a one-off attack. It's part of a growing trend where cybercriminals are getting more creative and more aggressive. They're combining tools, automating processes, and targeting real people with real money. The days of "it won't happen to me" are over. Staying safe isn't about being paranoid. It's about being smart. A few simple habits can make you a much harder target, and that's often enough to send attackers looking for an easier victim. So take a minute right now to check your NFC settings. It might be the most important thing you do today.