New Android malware relays bank cards to fraudsters while victims still hold them

2026-08-14T20:51:39Z778ec2fd5d1256cb42a0f57803b81dfaa6b3c1a2d4070837e348075ea8af1bfd
AI governanceAndroid malwareCyber Resilience ActNFC relay attackSpyNote RATWindRelaybank impersonationcloud IAM misconfigurationcyber fraudmobile malwarepayment card fraudremote access trojansocial engineering

What happened

The feed reports a new Android malware operation involving WindRelay, which captures live payment-card data over NFC and relays it to fraudsters in real time while the victim still possesses the card. WindRelay is used alongside the SpyNote Android remote-access trojan, with social engineering calls impersonating banks initiating the attack. Other items cover cloud IAM misconfiguration, fraud call-center disruption, cybersecurity regulation, and AI governance, but no specific vulnerability disclosures are identified.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
778ec2fd5d1256cb42a0f57803b81dfaa6b3c1a2d4070837e348075ea8af1bfd
Enrichment time
2026-08-14T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.