New Android malware relays bank cards to fraudsters while victims still hold them
2026-08-14T20:51:39Z•778ec2fd5d1256cb42a0f57803b81dfaa6b3c1a2d4070837e348075ea8af1bfd
AI governanceAndroid malwareCyber Resilience ActNFC relay attackSpyNote RATWindRelaybank impersonationcloud IAM misconfigurationcyber fraudmobile malwarepayment card fraudremote access trojansocial engineering
What happened
The feed reports a new Android malware operation involving WindRelay, which captures live payment-card data over NFC and relays it to fraudsters in real time while the victim still possesses the card. WindRelay is used alongside the SpyNote Android remote-access trojan, with social engineering calls impersonating banks initiating the attack. Other items cover cloud IAM misconfiguration, fraud call-center disruption, cybersecurity regulation, and AI governance, but no specific vulnerability disclosures are identified.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 778ec2fd5d1256cb42a0f57803b81dfaa6b3c1a2d4070837e348075ea8af1bfd
- Enrichment time
- 2026-08-14T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.