threat_intelligence362 wordsRead on Arc Codex

New Android Malware Can Steal Credit Card Data and Secretly Conduct Financial Transactions

439/69 Friday, August 14, 2026 Researchers from Group-IB have reported the discovery of a new threat targeting the Android operating system. This threat involves the combined use of WindRelay, a malware strain that relays data through Near Field Communication (NFC), and SpyNote, a Remote Administration Tool (RAT) used to control infected devices. The threat affects general users by allowing attackers to take control of devices, secretly carry out financial transactions such as applying for loans in the victim’s name, and steal credit card data in real time. The attack begins when the threat actors call victims while impersonating bank employees and claim that there is a problem with their payment cards. They then trick victims into installing an application containing SpyNote malware, disguised as a normal application, while using social engineering to persuade them to grant Accessibility Service permissions. This allows the attackers to remotely control the device. Once control is gained, the attackers secretly install WindRelay and proceed to apply for loans through the victim’s banking application. In a key step of the attack, the attackers trick the victim into placing their credit card against the back of the phone and entering the card PIN. The malware then turns the victim’s phone into a contactless card reader and relays NFC authentication data back to the attackers, allowing them to use it for real-world purchases. Reports indicate that the entire process can take as little as 30 minutes, with initial victims primarily observed in some European countries. To prevent and reduce the risk of this threat, Android users should avoid installing applications from external files that do not come from official app stores such as Google Play, unless the source is known and genuinely trusted. Users should also exercise caution when applications request access to NFC or other sensitive system permissions on the device. As an initial response measure, if users receive a phone call claiming to be from a bank and are pressured to take urgent action related to any transaction, they should hang up immediately. They should then contact the financial institution directly using the official phone number listed on the institution’s website to verify the matter with legitimate staff.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.