Breaking
AI Edge Daily Briefing — 11 August 2026AI Edge Daily Briefing — 22 July 2026Bursa Malaysia ends lower on profit-taking - The Malaysian ReserveBursa Malaysia holds steady after Wall St rally, crude oil price tumbles - The StarDT Infrastructure and Edify Energy Strengthen Renewable Partnership with North Queensland Solar ProjectsGamuda Recognised Among the World’s Most Sustainable Companies by TIME-Statista, Achieves Highest 4-Star FTSE4Good ESG Grading BandRosol accepts apology for doctored ‘bridal gown’ imageSARA aid may be expanded to cover vege and fruitsClimate groups flag budget tagging, allocation concernsInfluencers spark Cantonese revival; Stephen Chow’s comedy genius: 7 Lifestyle highlightsPHL employee turnover seen hitting 20% as workers seek more than pay — AscentHRGoogle Pixel 11 Pro Fold hadir dengan chip Tensor G6 dan desain tipisAI nuclear power firm Fermi finally has a new CEOBursa Malaysia Stays Lower At Mid-Morning - Bernama"City-Forum" data-theft attacks target Salesforce, ServiceNow portalsAndroid malware combo takes out loans and relays victims' credit cardsLawmakers flag gaps in proposed changes to building management rules after Tai Po fireScientists just created female clones of male miceJugendämter melden 10 % mehr Kindeswohlgefährdungen im Jahr 2025Attackers Exploit SharePoint Authentication Bypass After Public PoC ReleaseAI Edge Daily Briefing — 11 August 2026AI Edge Daily Briefing — 22 July 2026Bursa Malaysia ends lower on profit-taking - The Malaysian ReserveBursa Malaysia holds steady after Wall St rally, crude oil price tumbles - The StarDT Infrastructure and Edify Energy Strengthen Renewable Partnership with North Queensland Solar ProjectsGamuda Recognised Among the World’s Most Sustainable Companies by TIME-Statista, Achieves Highest 4-Star FTSE4Good ESG Grading BandRosol accepts apology for doctored ‘bridal gown’ imageSARA aid may be expanded to cover vege and fruitsClimate groups flag budget tagging, allocation concernsInfluencers spark Cantonese revival; Stephen Chow’s comedy genius: 7 Lifestyle highlightsPHL employee turnover seen hitting 20% as workers seek more than pay — AscentHRGoogle Pixel 11 Pro Fold hadir dengan chip Tensor G6 dan desain tipisAI nuclear power firm Fermi finally has a new CEOBursa Malaysia Stays Lower At Mid-Morning - Bernama"City-Forum" data-theft attacks target Salesforce, ServiceNow portalsAndroid malware combo takes out loans and relays victims' credit cardsLawmakers flag gaps in proposed changes to building management rules after Tai Po fireScientists just created female clones of male miceJugendämter melden 10 % mehr Kindeswohlgefährdungen im Jahr 2025Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Economy

Android malware combo takes out loans and relays victims' credit cards

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]

Source: BleepingComputer · August 13, 2026 at 7:45 AM · AI-assisted report

Android malware combo takes out loans and relays victims' credit cards
Image: bleepingcomputer.com

KUALA LUMPUR, 13 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

**Android Malware Combo Targets Malaysian Users in NFC Relay Attacks**

Market Impact

A sophisticated Android malware combination, WindRelay and SpyNote, is being used to steal live credit card data and initiate unauthorized loans, cybersecurity firm Group-IB has warned. The attack involves social engineering over a 13-minute phone call, where victims are tricked into installing malicious software and revealing their PIN, enabling real-time fraud.

The operation begins with a fraudster impersonating a bank employee, instructing the victim to sideload the SpyNote remote access tool disguised as a legitimate app. Once installed, SpyNote grants attackers full control over the device, including the ability to install additional malware like WindRelay. The victim is then manipulated into tapping their payment card on the infected phone, allowing WindRelay to relay NFC transaction data to the attacker’s device.

This data is used to make fraudulent purchases at legitimate payment terminals.

Group-IB identified nearly two dozen WindRelay samples uploaded to VirusTotal between November 2025 and July 2026, linked to four command-and-control servers. While the primary targets appear to be Czechia, Slovakia, and Slovenia, cybersecurity experts warn that similar tactics could spread globally, including Malaysia. The malware’s ability to bypass traditional security measures makes it a growing threat to mobile banking users.

For Malaysian consumers, the risks are significant. Android users are advised to avoid sideloading apps from untrusted sources and to scrutinize requests for NFC access or sensitive permissions. Banks in Malaysia have previously warned about phishing scams involving fake customer service calls, urging users to verify callers by contacting their bank directly via official channels.

The SpyNote malware family, which has circulated since 2021, has seen increased detections following a 2022 source code leak. It can steal banking credentials, account logins, and even activate device cameras and microphones. When combined with WindRelay’s NFC relay capabilities, attackers can execute fraud without needing advanced technical skills, relying instead on social engineering.

Cybersecurity experts emphasize that traditional prevention methods may fail once attackers gain access through valid credentials. Group-IB’s *Blue Report 2026* highlights that defense effectiveness drops sharply after initial compromise. Malaysian financial institutions and regulators are expected to reinforce warnings about such scams, particularly as digital banking adoption rises in the country.

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.