Security advisory
Mobile ThreatsHighActiveUpdated Aug 23, 2026

SpyNote and WindRelay Combo Empties Bank Accounts via NFC Relay Fraud

Researchers say the SpyNote-WindRelay toolkit pairs remote device control with live NFC card relay, turning one phone call into both a fraudulent loan and a cloned contactless payment.

Emanuel De AlmeidaAug 23, 2026, 9:48 PM7 min read
Severity
High
Status
Active
Entity
SpyNote / WindRelay malware combination
Confirmed by
Group-IB

A new Android NFC relay malware called WindRelay is being paired with the SpyNote remote administration tool (RAT) to apply for fraudulent loans and relay victims' live payment card data to attackers, according to research published by Group-IB. In the incident the firm investigated, a fraudster posing as a bank employee walked a victim through sideloading SpyNote disguised as a legitimate, personalized app, then silently deployed WindRelay to complete the theft.

The case matters because it shows attackers combining remote device takeover with live NFC card cloning in a single call, extracting both a loan and cash-out capability without the screen-sharing tools most Android banking malware relies on.

Key takeaways

  • Group-IB documented SpyNote and a new NFC relay tool, WindRelay, used together in one fraud incident.
  • The attacker impersonated a bank employee by phone and convinced the victim to sideload SpyNote with Accessibility permissions.
  • WindRelay turned the compromised phone into a fraudulent contactless reader, relaying live NFC card data to the attacker in real time.
  • The entire loan application and card relay occurred within a single 13-minute phone call.
  • Group-IB found nearly two dozen WindRelay samples on VirusTotal between November 2025 and July 2026, with targeting concentrated on Czechia, Slovakia, and Slovenia.

Affected

Products
Android OS
Malware
SpyNoteWindRelaySpyMaxCypherRAT
Geography
CzechiaSlovakiaSlovenia
Industry
Banking and financial services

What did Group-IB find in the SpyNote-WindRelay case?

WindRelay is a newly identified Android NFC relay tool that Group-IB observed being deployed alongside the established SpyNote remote administration tool in a live fraud case. According to the researchers, an attacker called a victim while posing as a bank employee, claiming there was a problem with their payment card. During the call, the victim was talked into sideloading an app disguised as a legitimate tool, personalized with the victim's own name to appear credible, and granting it Accessibility Service permissions.

That sideloaded app was SpyNote, which gave the attacker full remote access to the device. Without any further action from the victim, the attacker then installed WindRelay silently and used the victim's own banking app to apply for a loan in their name. Group-IB says the entire sequence, from the initial call to the completed fraud, took 13 minutes.

How does WindRelay relay live card data?

While the loan application ran in the background, the caller instructed the victim to tap their physical payment card against the phone and enter its PIN. WindRelay turned the compromised device into a fraudulent contactless reader, capturing the live NFC exchange, including transaction-specific authentication data generated for that session, and streaming it in real time to the attacker's own device.

The attacker then used that relayed data to authorize a purchase at a genuine point-of-sale terminal, with the transaction approved using the same PIN the victim had just entered. Group-IB notes this differs from most current Android banking malware, which typically relies on live screen sharing or VNC-style remote viewing; here, the fraud ran entirely on Accessibility-based remote control plus a phone-call script, without the attacker ever seeing the victim's screen in real time.

Why does pairing a RAT with an NFC relay matter?

Group-IB's researchers say the SpyNote-WindRelay pairing suggests a toolkit built to serve two fraud paths from one compromise: using SpyNote's device access to move money directly through the victim's banking app, and using WindRelay as a parallel cash-out channel through cloned card transactions at physical terminals. That dual capability increases the total loss per victim compared with malware that only supports one fraud method.

It also lowers the bar for attackers, since the scheme depends on social engineering and permission abuse rather than exploiting a software vulnerability. A victim who trusts the caller and follows instructions can be defrauded through a legitimate banking app and a legitimate payment terminal simultaneously, without either system flagging anything unusual at the point of transaction.

Who is being targeted?

  • Group-IB identified nearly two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026.
  • Those samples communicated with four distinct command-and-control IP addresses, according to the researchers.
  • Based on the organizations impersonated and the languages used in the malicious apps, targeting appears concentrated on Czechia, Slovakia, and Slovenia.

The SpyNote RAT itself is not new: it and variants such as SpyMax and CypherRAT have circulated since at least 2021, with a documented rise in detections in late 2022 and early 2023 following a leak of the malware's source code, per BleepingComputer's reporting on Group-IB's research. SpyNote's broader capabilities include stealing banking, Facebook, and Google credentials, harvesting Google Authenticator codes, tracking GPS location, intercepting SMS messages, and activating the device microphone and camera.

How does this fit the wider Android NFC relay malware trend?

WindRelay joins a growing list of Android NFC relay families documented in 2025 and 2026, including NFCShare, NGate, SuperCard X, and RelayNFC. In the typical version of this attack, a victim installs a malicious app and grants it NFC access, then a caller uses social engineering to get them to tap their card against the compromised phone. The phone reads the contactless card data and forwards it over the internet to the attacker's device, where it can be used for point-of-sale purchases or, depending on the data captured, ATM withdrawals.

Separately, BleepingComputer has reported on another active Android threat, Manic malware, which ThreatFabric says has targeted at least 169 banking, government, payment, and crypto-wallet apps since at least February 2026, focused primarily on users in Ukraine. Manic uses Accessibility-based keylogging and an unusual peer-to-peer exfiltration mechanism over Wi-Fi Direct or Bluetooth when it cannot reach its command-and-control server, illustrating how quickly Android fraud tooling is diversifying beyond simple overlay attacks.

What can Android users do to avoid this fraud?

  • Avoid installing APK packages from outside Google Play unless the publisher is known and trusted.
  • Be cautious with any app that requests NFC access or Accessibility Service permissions, especially one received or suggested during an unsolicited phone call.
  • If a caller claiming to be from your bank asks for urgent action, end the call, dial the number listed on the bank's official website, and ask to be connected to the same support agent.
  • Treat any request to tap your payment card against your phone during a phone call as a red flag, since banks do not need customers to do this to resolve card issues.

Timeline

Nov 1, 2025
Earliest WindRelay samples appearGroup-IB says the earliest WindRelay samples it identified on VirusTotal date to November 2025, part of a set of nearly two dozen samples collected through July 2026.
Aug 12, 2026
Group-IB publishes SpyNote-WindRelay researchGroup-IB details an incident where a caller impersonating a bank employee used SpyNote and WindRelay together to take out a loan and relay live card data within a 13-minute call.

Impact & actions

Victims can lose money twice in one call: a fraudulent loan issued through their own banking app, and a cloned live NFC transaction used at a real payment terminal.

Security: Unlike most modern Android malware that relies on live screen sharing or VNC sessions, this toolkit enabled the attackers to commit fraud through social engineering over the phone combined with Accessibility abuse and NFC relay.

Privacy: Beyond financial data, SpyNote variants can access SMS, GPS location, Google/Facebook credentials, Authenticator codes, camera, and microphone once Accessibility permissions are granted.

Recommended actions · High urgency

  1. 1Never sideload an APK sent or requested during an unsolicited bank phone call
  2. 2Deny or revoke Accessibility Service permissions for any app outside Google Play
  3. 3Hang up on callers claiming to be from your bank and redial the number listed on the bank's official website
  4. 4Treat any request to tap your payment card against your phone and enter a PIN during a call as a fraud indicator

Technical details

Exploitation
Exploited in the wild
Attack vector
Voice-phishing call impersonating a bank employee, followed by victim-initiated sideloading of a personalized SpyNote APK granted Accessibility Service permissions, which is then used to silently install WindRelay for NFC relay and loan fraud.

Indicators of compromise

Other
Four command-and-control IP addresses — Group-IB identified roughly two dozen WindRelay samples on VirusTotal (November 2025-July 2026) communicating with four C2 IP addresses.

Mitigations

  • Avoid installing APK packages from outside Google Play unless the publisher is known and trusted
  • Deny NFC access and other sensitive permissions to apps that request them without clear justification
  • Terminate suspicious bank calls and redial using the number on the institution's official website

Response

Customer guidance

Group-IB and BleepingComputer advise against sideloading APKs during unsolicited bank calls, recommend denying Accessibility and NFC permissions to untrusted apps, and urge hanging up and calling the bank's official number to verify any support agent.

FAQ

What is WindRelay malware?

WindRelay is a newly identified Android NFC relay tool that turns an infected phone into a fraudulent contactless card reader, capturing live payment authentication data and sending it to an attacker's device in real time, according to Group-IB.

How is SpyNote used alongside WindRelay?

Attackers first trick victims into sideloading SpyNote, disguised as a personalized legitimate app, and granting it Accessibility Service permissions for remote device control. SpyNote is then used to silently install WindRelay without further victim interaction.

How long did the fraud incident Group-IB investigated take?

Group-IB says the entire fraudulent loan application and live NFC card relay occurred within a single 13-minute phone call, with the attacker impersonating a bank employee.

Which countries are being targeted by SpyNote and WindRelay?

Based on the organizations impersonated and languages used in the samples, Group-IB says targeting is concentrated on Czechia, Slovakia, and Slovenia.

How can Android users protect themselves from this fraud?

Avoid sideloading APKs outside Google Play, deny Accessibility and NFC permissions to untrusted apps, and hang up on unsolicited bank calls, then redial using the number listed on the bank's official website.

Is WindRelay related to other NFC relay malware families?

Group-IB places WindRelay alongside a growing set of Android NFC relay tools including NFCShare, NGate, SuperCard X, and RelayNFC, which use similar tap-to-relay techniques against contactless payment cards.

The bottom line

Group-IB documented a case where SpyNote and a new NFC relay tool, WindRelay, were combined to file a fraudulent loan and relay live card data in a single 13-minute call.

What to do

Never sideload an app or tap your card to your phone during an unsolicited bank call; hang up and call your bank's official number instead.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles