Digital transformation

Warning: New Android malware steals bank card data in a sophisticated manner.

Phan Van Hoa August 18, 2026 08:01

A new Android malware is exploiting fake bank calls to trick users into installing malicious apps, thereby secretly stealing card data and making unauthorized transactions.

Security experts have just discovered a sophisticated Android attack campaign in which hackers combine the SpyNote remote control malware with WindRelay to gain control of phones and commit payment fraud via near-field communication (NFC) technology.

Ảnh minh họa154
Illustrative image.

According to Group-IB, a cybersecurity company specializing in researching and responding to cyber threats, WindRelay was detected active from the end of August 2025. To date, researchers have recorded 23 malware samples uploaded to the VirusTotal threat intelligence platform, mostly impersonating financial institutions.

The fake bank call is the first step.

The attackers don't directly distribute malware; instead, they first try to deceive victims through psychological tactics.

Scammers may call, text, or use other forms of impersonation to contact victims, often posing as bank employees. After gaining trust, they ask victims to install an Android app under the pretext of identity verification, account troubleshooting, or card protection.

Notably, the Android app installation file (APK) sent to the victim can be personalized with their own name. This makes the call more convincing and suggests the attacker may have pre-collected information such as the victim's phone number and name.

This is also an important warning: an app with a name and information that matches a user's does not necessarily mean it is legitimate.

After the victim installs the malicious application, SpyNote – a type of remote access malware (RAT) – can be used to gain control.control of the device.

With this access, the attacker can remotely manipulate the phone and silently activate WindRelay without the victim's knowledge. Notably, this process does not require the use of the screen sharing feature.

WindRelay then undertook a particularly dangerous mission: to turn the infected phone into a link in a contactless payment attack.

Mobile phones are being used as a "bridge" to steal bank card information.

If the victim follows the scammer's instructions and brings the bank card close to the phone for "verification," WindRelay can use NFC to read the data exchanged between the card and the device.

This data is transmitted in real time to the attacker's device elsewhere.

Essentially, the system consists of two components. One component resides on the victim's phone, reading data from the card via NFC. The other component is located on the attacker's device, simulating the card at a payment terminal. Both sides exchange data through the attacker's control infrastructure.

This allows fraudsters to carry out transactions without the victim's direct involvement.

Ảnh minh họa155
Mobile phones are being used as a "bridge" to steal bank card information. Photo: Internet

The dangerous aspect of the WindRelay campaign lies in the fact that hackers combined multiple fraudulent methods in a single attack.

While WindRelay facilitates card payment fraud, SpyNote offers remote device control capabilities. According to Group-IB, attackers can also leverage this control to carry out other financial frauds, such as applying for digital loans.

Thus, victims not only face the risk of losing money from their cards but may also have their identity and financial accounts exploited.

Android users need to be especially vigilant against malware.

The worrying thing is that there were no technical signs that were too complex for the victim to detect. The most difficult part of the attack lay in psychological manipulation.

Users should be especially wary if they receive a call from someone claiming to be a bank employee and requesting:

- Install the app from the APK file sent via text message or phone call.

- Granting access to an application from an unknown source.

- Hold your bank card close to your phone to "verify".

- Provide the OTP code, PIN code, or card information.

- Allows strangers to remotely control or access your phone.

In particular, it should be noted that banks have no legitimate reason to ask customers to install an application of unknown origin based on instructions given over the phone.

Users should also prioritize installing apps from Google Play, regularly update Android and banking apps, and check the special permissions that apps are granted.

If you have followed suspicious instructions, you should disconnect from the internet, uninstall the malicious app if possible, contact your bank immediately to block your card/account, and check for unusual transactions.

This new attack campaign shows that malware on smartphones is evolving; instead of just stealing passwords or messages, it can turn the victim's phone into a tool for real-time fraudulent transactions.

Therefore, in many cases, being vigilant against a fraudulent bank call can be just as important as installing security software.

Phan Van Hoa