New Android Malware Uses Bank Cards in Real Time, Raising New Fraud Risks for UK SMEs

SECURUS Communications Ltd

Securus is a managed communications Operator, providing next-generation network infrastructure and value added services to Managed Hosting providers and the ‘cloud generation’​ of enterprises. Securus priority is to offer communication services that represent excellent value for money and are backed by exceptional levels of support.

Contact Securus
Securus Communications Ltd
Station Road, Landmark house, Hook, England RG27 9HA, GB
T: Enquiries:  | Service Desk: 03451 283458
Securus on LinkedIn | Securus on “X” | https://securuscomms.com

New Android Malware Uses Bank Cards in Real Time, Raising New Fraud Risks for UK SMEs
Image Credit: DC Studio via Magnific

Gibraltar:  Monday, 21 September 2026 – 07:00 CET

New Android Malware Uses Bank Cards in Real Time, Raising New Fraud Risks for UK SMEs
By: Iain Fraser – Cybersecurity Journalist
Published in Collaboration with:
Securus Communications Ltd
SMECyberInsights.co.uk – First for SME Cybersecurity
Google Indexed on: 210926 at 08:50 CET | SERPS: LLM(AI) Google
#CyberJourno #CyberEssentials #CyberResilience #CyberSafe #CyberSecurity #Cybersecurity #NCSC #SME #SMECyberInsights #SMECybersecurity #SMECyberInsights #ThreatIntelligence #Securus

New Android Malware Uses Bank Cards in Real Time, Creating Serious Fraud Risks for UK SMEs

A new Android threat reported by Malwarebytes shows how mobile fraud is becoming more coordinated, more persuasive, and more dangerous for SMEs. This is not just a case of stolen passwords or fake apps. It is a live fraud technique that can let criminals abuse a victim’s bank card in real time, blending social engineering, remote phone control, and contactless payment abuse.

What the attack does

According to Malwarebytes, citing research from Group-IB, the attack uses two malicious tools: SpyNote, a remote access Trojan, and WindRelay, an NFC relay malware family.

NFC, or Near Field Communication, is the short-range wireless technology used by contactless bank cards and mobile payment systems. In the reported attack, criminals do not need to steal the physical card. Instead, they persuade the victim to install a fake banking app on an Android phone, gain remote access, and then relay card data from the victim’s device to a separate criminal-controlled device.

Malwarebytes highlights the core issue clearly: “The remote-access malware (SpyNote) gets the attackers into the phone, and the NFC relay malware (WindRelay) turns the victim’s physical card into something the criminals can use elsewhere at that moment.”

Why this matters for SMEs

For UK SMEs, this matters because business owners and finance staff often use the same mobile device for email, messaging, banking, and payment approvals. That creates concentration risk. One successful compromise can affect several business functions at once.

The reported incident also involved a 13-minute call impersonating a bank, showing how believable and patient these attacks can be. The attackers reportedly opened the victim’s real banking app remotely, arranged a loan in the victim’s name, then asked them to tap their physical payment card against the infected phone and enter the PIN.

That is a significant shift. Fraud is no longer just about harvesting credentials. It is about manipulating the victim step by step while malware handles the technical work in the background.

New Android Malware Uses Bank Cards in Real Time, Raising New Fraud Risks for UK SMEs

Practical guidance for UK SMEs

SMEs do not need expensive tools to reduce this risk, but they do need stronger process discipline.

Prioritise these actions:

* never install apps from links sent by text, email, or callers
* end unsolicited banking calls and contact the bank using trusted details
* keep Android devices updated and protected with reputable mobile security software
* separate business banking from general-use phones where possible
* require dual approval for high-value payments or account changes
* review banking alerts and unusual loan or payment activity promptly

This also supports broader good practice from the NCSC and Cyber Essentials, especially around secure configuration, access control, and user awareness.

FAQs

What is WindRelay malware?

WindRelay is a reported Android NFC relay malware family identified by Group-IB and covered by Malwarebytes. It is designed to capture contactless card data through an infected phone and forward that data in real time to criminals, allowing fraudulent transactions and potentially contactless ATM cash withdrawals.

How do attackers get victims to install this malware?

The reported method relied on a convincing social engineering call. Attackers impersonated a bank, created urgency, and persuaded the victim to install a fake Android app carrying the bank’s name. That app acted as an entry point for remote access and the silent installation of further malicious software.

Why is this especially dangerous for SMEs?

SMEs often rely on a small number of trusted individuals to manage payments, banking, and approvals. If the same Android phone is used for both day-to-day communications and financial activity, one compromise can quickly create financial loss, operational disruption, and wider trust issues inside the business.

What should SMEs do first to reduce the risk?

Start with behaviour and process controls. Staff should never install apps during a live call, should verify banking requests independently, and should avoid using the same phone for both everyday use and business banking where possible. Strong payment approval controls provide another important safeguard.

FAQ note: These FAQs are based on recurring live audience questions and discussion themes from Reddit and Quora, helping ensure each article answers what SME readers are actively asking in the real world.

Conclusion

This Android malware case is a useful warning for SMEs because it shows how fraud now blends human manipulation with technical precision. Mobile devices are no longer peripheral to Cybersecurity risk. For many SMEs, they sit at the centre of communication, identity, and payments. The practical lesson is simple: tighten mobile security, strengthen approval processes, and train staff to distrust urgency dressed up as customer service.

What is a VPN & Does my SME Need one? A VPN is a Virtual Private Network a method of securing your communications credentials. When it comes to SMEs, the choice of VPNs can significantly impact the security and efficiency of their operations. NordVPN secures your Internet data with military-grade encryption, ensures your activity remains private and helps bypass geographic content restrictions online.   Join NordVPN Today and Save up to 73% and Get 3 months Extra Free – Rude Not to …!

CYBERInsights | Practical Small Business Cybersecurity
Image Credit: IfOnlyCommunications

SMECYBER Insights – Helping Keep Small Business CYBERSafe! 

Launched in 2020 by Cybersecurity Journalist Iain Fraser and his team at IfOnly… SMECYBERInsights was developed to be the go-to platform providing definitive, reliable & actionable Cybersecurity News, Intel,  Awareness & Training specifically written and curated for Small Business & Enterprise Owners, Partners and Directors throughout the UK. #SMECyberInsights #SMECyberSecurity #CyberAttack #CyberAwareness  #Compliance #DDoS #Fraud #Ransomware #ScamAlert #SME #SmallBusiness #SmallBusinessOwner #ThreatIntel  

Author