Published Security3 min read
One 13-Minute Call, Two Payouts: WindRelay and SpyNote Collapse the Malware/Scam Split
Group-IB documented a single call in which a fake bank employee seeded a SpyNote RAT labelled with the victim's own name, then installed NFC relay malware himself. No screen sharing was triggered.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Group-IB documented the case in a technical write-up published on August 12, tracking the NFC relay malware as WindRelay and attributing the remote access trojan to a variant of SpyNote; the attack occurred within a single 13-minute phone call.
- The combination let a fraudster take out a loan in the victim's name and relay their card data to a fake terminal while keeping the victim on the line.
- The fraudster called posing as a bank employee reporting a problem with the victim's card, then talked them through installing the first app.
- The RAT arrived through the device's package installer, the standard route for sideloading outside an app store.
- The RAT's app label carried the victim's own name, rather than a generic or impersonated brand.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Group-IB published a technical write-up on August 12 documenting a previously unseen NFC relay malware family, which it tracks as WindRelay, deployed alongside a variant of the SpyNote remote access trojan inside a single 13-minute phone call [1]. In that window the fraudster took out a loan in the victim's name and relayed their card data to a fake terminal while keeping them on the line [2].
The entry was ordinary. The caller posed as a bank employee reporting a problem with the victim's card and talked them through installing the first app [3]. That app was the RAT, and it arrived through the device's package installer, the standard route for sideloading outside an app store [4].
The detail worth carrying into your own detection review is the label. The app's name was the victim's own name, not a generic string or an impersonated bank brand [5]. SpyNote ships with a builder toolkit that lets an operator set a custom app name, label and package name, so this is configuration rather than craftsmanship [6]. Group-IB read the label as evidence of pre-call reconnaissance that harvested the victim's name and phone number, and noted it left no unfamiliar app name to give the victim pause [7].
From there the human stopped being needed. With the RAT active, the fraudster used its remote access to install WindRelay himself, requiring nothing further from the victim [8]. No screen sharing was triggered at any point in the session [9]. Any control that watches for screen-share activation as a stand-in for remote control saw a clean call.
WindRelay's permission set is a fair statement of intent: NFC to read the card, INTERNET to stream captures out live, READ_CONTACTS to reach further targets, and DUMP, which Group-IB flags as unusual in a third-party app, to inspect device state [10]. When the victim tapped their card as instructed, the malware acted as a contactless reader and captured the live exchange between chip and reader, including the one-time code generated for that transaction [11]. That exchange was streamed to a second device held by the fraudster, which presented itself as the card to a real terminal [12].
The loan came through the same access, via the victim's banking app, and Group-IB reads it as an opportunistic add-on rather than a planned step [13]. Card transactions began appearing shortly after the call ended [14]. Two separate monetisation paths, account credit and card present, ran off one installation session [15].
This is not a one-off. Group-IB linked WindRelay to 23 samples uploaded to VirusTotal between November 2025 and July 2026, impersonating institutions in Czechia, Slovakia and Slovenia [16] - roughly a nine-month spread of activity across three markets [17].
What to watch: Group-IB's own recommendations are the practical test of whether your controls are wired for this. Stop treating screen-sharing detection as a proxy for remote access, alert on app installations from non-official sources during an active call, and flag loan disbursements that coincide with physical card transactions [18]. The middle one requires telephony state and install events in the same rule, which is where most mobile fraud stacks are still split by team. The third requires the lending and card authorisation sides of the bank to correlate in near real time, on a 13-minute clock [1].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Group-IB documented the case in a technical write-up published on August 12, tracking the NFC relay malware as WindRelay and attributing the remote access trojan to a variant of SpyNote; the attack occurred within a single 13-minute phone call.
- [2]
The combination let a fraudster take out a loan in the victim's name and relay their card data to a fake terminal while keeping the victim on the line.
ReportedView cited source - [3]
The fraudster called posing as a bank employee reporting a problem with the victim's card, then talked them through installing the first app.
ReportedView cited source - [4]
The RAT arrived through the device's package installer, the standard route for sideloading outside an app store.
ReportedView cited source - [5]
The RAT's app label carried the victim's own name, rather than a generic or impersonated brand.
ReportedView cited source - [6]
SpyNote ships with a builder toolkit letting an operator set a custom app name, label and package name, so personalization is built in rather than manual effort.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- infosecurity-magazine.comAug 12WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam
Additional citations
- Group-IB, via Infosecurity Magazine
- Group-IB



