[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQlvZ6h2Oigj9WD11i5IURoSCXIntJRi_KUpqpbtTz0o":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"89b527d1-074b-4faa-a67b-b9b5fe678b8b","android-malware-duo-steals-card-data-and-enables-fraudulent-loans-via-nfc-relay","fab7e104-b826-4da3-a26b-5c957ceb6d2f","Android Malware Duo Steals Card Data and Enables Fraudulent Loans via NFC Relay","Attackers combined SpyNote RAT and WindRelay malware to execute a sophisticated two-stage attack: social engineering tricks victims into sideloading SpyNote, which grants remote access, while WindRelay silently relays NFC payment card data in real time during a fake payment interaction. This attack is particularly dangerous because it bypasses traditional card-not-present fraud controls by using the victim's physical device as a live relay, making fraudulent transactions appear legitimate. The root failure lies in victims' inability to recognize social engineering tactics and the permissive nature of Android sideloading. This matters because financial losses can be immediate and difficult to reverse, and victims may not realize they've been compromised until significant damage is done.","**Immediate actions:**\n- Disable the ability to install apps from unknown sources (sideloading) on all personal and corporate Android devices.\n- Educate users to never grant Accessibility, NFC, or remote-control permissions to apps received via links, SMS, or unsolicited messages.\n- Report and revoke any suspected compromised devices immediately and contact your financial institution to freeze affected cards.\n\n**Long-term improvements:**\n- Enforce a Mobile Device Management (MDM) policy that restricts app installation to approved stores and allowlisted applications only.\n- Implement NFC payment controls at the banking\u002Fcard-issuer level to flag or block relay-pattern transactions in real time.\n- Conduct regular security awareness training focused on mobile-specific social engineering tactics, including fake app installs and impersonation scams.\n\n**Detection measures:**\n- Deploy mobile threat defense (MTD) solutions that detect RAT behavior, unusual NFC activity, and unauthorized screen-sharing on endpoints.\n- Monitor banking accounts and card transactions with real-time alerts for any transaction initiated in an unexpected geographic location or device profile.\n- Establish anomaly detection at the network level for unusual data relay patterns originating from mobile devices on corporate networks.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 4 – Secure Configuration of Enterprise Assets","CIS Control 14 – Security Awareness and Skills Training","NIST SP 800-124 – Guidelines for Managing the Security of Mobile Devices","NIST PR.AT-1 – Security Awareness Training","NIST AC-17 – Remote Access Controls","GDPR Article 32 – Security of Processing (for organizations handling personal financial data)","PCI DSS Requirement 12.6 – Security Awareness Program","PCI DSS Requirement 8 – Identify and Authenticate Access to System Components","ITIL – Service Operation: Event Management for anomaly detection","published","2026-08-13T00:20:41.360897+00:00","2026-08-13T00:20:41.041+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fandroid-malware-combo-takes-out-loans-and-relays-victims-credit-cards\u002F","android-malware-combo-takes-out-loans-and-relays-victims-credit-cards-f2480e","Android malware combo takes out loans and relays victims' credit cards",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[49],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"3e71b418-a7ec-4813-aca4-dad8cf676f44","2026-08-13","morning","ThreatNoir Morning Brief — August 13","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-13\u002Fthreatnoir-morning-brief-2026-08-13.mp3"]