
Scammers are draining bank accounts and pulling cash from ATMs without needing the victim’s debit card in hand.
Experts at the cybersecurity firm Group-IB say they have uncovered a previously unseen Android malware family they are calling WindRelay, built to capture live near-field communication (NFC) payment data and forward it in real time to attackers.
On a call that lasts about 13 minutes, someone posing as a bank worker talks the victim into installing an app. That app lets the scammer take over the phone and quietly add WindRelay.
Once both tools are on the device, scammers open the victim’s real banking app, arrange loans and tell the target to tap their payment card against the phone and enter the PIN.
WindRelay turns the phone into a fake contactless reader. The live tap, including the one-time code from the card, is streamed to a device the criminals hold against an ATM or store terminal. The tap then goes through as if the real card were there.
Says Group-IB,
“In one 13-minute phone call, the victim installed a RAT onto their own device — everything after that was performed by the fraudster. By the end of the call, the fraudster had taken out a loan in the victim’s name through remote access to the victim’s mobile app, and was streaming their card data to a fake merchant terminal.”
Researchers tied 23 WindRelay samples uploaded to VirusTotal between November of 2025 and July of 2026 to campaigns aimed at bank customers in Czechia, Slovakia and Slovenia. They linked the samples to four command-and-control servers.
Follow us on X, Facebook and Telegram
Don't Miss a Beat – Subscribe to get email alerts delivered directly to your inbox
Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any assets including cryptocurrencies, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.
Generated Image: Midjourney
The post New Android Malware Lets Scammers Drain Bank Accounts and ATMs – Without Stealing Your Bank Card appeared first on The Daily Hodl.



Comments (0)
Please sign in to comment.
No comments yet. Be the first to comment.