Published Security3 min read
Card-present fraud without the card: WindRelay relays NFC from the victim's own phone
Group-IB says a 13-minute call ended with a loan in the victim's name and card data streaming to a fake merchant terminal, every transaction approved with the victim's own PIN.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Group-IB researchers discovered WindRelay, new Android malware built to capture live payment card data over NFC and relay it to attackers in real time.
- WindRelay is paired with the SpyNote remote access trojan, which gives attackers remote access to the victim's device.
- The scam starts with a phone call in which the fraudster claims to be from the victim's bank and says there is a problem with their card; guided step by step, the victim installs an app themselves.
- The app the victim installs is SpyNote, and its label shows the victim's own name instead of a strange or generic one.
- Group-IB researchers found that SpyNote's builder toolkit lets an operator customize the app's label, name and package for each target before deployment.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Group-IB researchers have documented WindRelay, Android malware built to capture live payment card data over NFC and relay it to attackers in real time [1], deployed alongside the SpyNote remote access trojan for control of the handset [2]. If a contactless read plus a correct PIN is treated anywhere in your stack as evidence that the card and its holder were standing at a terminal, this campaign produced both while the card stayed with the victim [1][10].
The entry point is a phone call. The fraudster claims to be from the victim's bank, says there is a problem with the card, and walks the victim through installing an app themselves [3]. That app is SpyNote, and it carries one detail designed to lower resistance: the app label shows the victim's own name rather than something generic [4]. Group-IB found that SpyNote's builder toolkit lets an operator set the label, name and package per target before deployment [5]. Once remote access is live, the fraudster installs WindRelay on the device with no further action from the victim [6]. WindRelay talks to the payment card over NFC and uses the phone's internet connection to relay that exchange as it happens [7]. It also asks for the victim's contacts and a system-inspection permission that is unusual for a third-party app [8].
The single-session outcome is the part worth reading twice. According to Group-IB, in one 13-minute call the victim installed the RAT onto their own device and everything after that was performed by the fraudster; by the end of the call the fraudster had taken out a loan in the victim's name through remote access to the victim's mobile banking app, and was streaming card data to a fake merchant terminal [9]. Every transaction was approved using the PIN the victim had entered themselves, and the victim remained on a live call for the entire incident [10]. Card transactions began appearing on the account shortly after the call ended [11].
Consider what the issuer sees. The card is genuine, the contactless exchange is real, the PIN is verified, and the loan application arrives from the customer's own registered handset over the banking app [7][9][10]. None of that resembles card-not-present abuse, and the device that would normally serve as a second factor is the attacker's console. Physical-presence signals are not being spoofed here so much as re-sourced: the tap is authentic and simply happens somewhere other than where the money moves [1][7].
Scale is modest but sustained. Group-IB traced 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026 [12], a nine-month window [1], tied to campaigns against victims in Czechia, Slovakia and Slovenia [13]. Researchers identified four command-and-control IP addresses associated with the NFC relay activity [14]. Several samples carried victim-specific names and interface text in the language of the target country, indicating per-victim tailoring [15]. Group-IB's own summary is that the fraudster combined three capabilities in a single session: a live social engineering call, a personalised RAT for remote device control, and NFC relay malware for physical cash-out [16].
Watch whether the three-country footprint widens, and whether the sample count moves faster than the nine months it took to reach 23 [12][1]. Watch also whether issuers begin scoring taps that originate from a cardholder's own handset differently from taps at a terminal, because on this evidence the two are currently indistinguishable [1][7].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Group-IB researchers discovered WindRelay, new Android malware built to capture live payment card data over NFC and relay it to attackers in real time.
- [2]
WindRelay is paired with the SpyNote remote access trojan, which gives attackers remote access to the victim's device.
- [3]
The scam starts with a phone call in which the fraudster claims to be from the victim's bank and says there is a problem with their card; guided step by step, the victim installs an app themselves.
- [4]
The app the victim installs is SpyNote, and its label shows the victim's own name instead of a strange or generic one.
- [5]
Group-IB researchers found that SpyNote's builder toolkit lets an operator customize the app's label, name and package for each target before deployment.
- [6]
Once SpyNote has remote access, the fraudster installs a second app, WindRelay, on the device without further action from the victim.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- helpnetsecurity.comSinisa MarkovicAug 14New Android malware relays bank cards to fraudsters while victims still hold them
Additional citations
- Group-IB, via Help Net Security
- Group-IB



