A new Android fraud campaign demonstrates how mobile malware is becoming more advanced, combining remote access spyware with NFC relay tools to steal payment data, apply for loans, and bypass traditional security measures.
Cybersecurity researchers say a new Android fraud campaign is showing how mobile malware is evolving beyond simple card theft. In a case investigated by Group-IB, attackers combined remote access spyware with an NFC relay tool to raid payment cards and, more unusually, use the victim’s own banking app to apply for loans. The attack began with a phone call from someone posing as a bank employee, a reminder that social engineering remains the easiest way into a device.
Once the target was persuaded to install the SpyNote remote-access trojan and grant Accessibility permissions, the attacker was effectively inside the handset. Group-IB said the malware then helped install WindRelay, a second payload designed to relay contactless payment data. At the same time, the caller instructed the victim to tap a physical card to the phone and enter a PIN, allowing the attackers to capture live authentication data and pass it on to a separate device for misuse at payment terminals.
The technique echoes earlier Android banking threats that have abused NFC and Android’s accessibility features. Malwarebytes has previously reported on NGate, which siphons card details and PIN data to enable unauthorised ATM withdrawals, while later campaigns such as Rokarolla have targeted hundreds of banking and crypto apps with fake overlays, keylogging and screen recording. Other families, including Escobar and Sturnus, have shown how attackers can steal one-time codes, monitor messages and remotely control infected phones. Together, these cases suggest mobile banking fraud is becoming more layered and more automated.
Security researchers continue to advise users to avoid sideloading apps from untrusted sources, because malicious software is often distributed outside the Play Store through fake support messages, spoofed websites or social media links. They also warn consumers to be sceptical of unsolicited calls claiming to be from a bank. A safer response is to hang up and ring the institution back using an official number, rather than following instructions from someone who may be trying to take control of the device or authorise transactions in the background.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





