Published Security3 min read
Thirteen minutes: WindRelay and SpyNote turn one scam call into a loan and a card-present purchase
Group-IB documented an Android pairing in which a remote access trojan arranged credit in the victim's name while a second implant relayed live contactless cryptograms to a mule standing at a real terminal.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Researchers at Group-IB discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers, which they named WindRelay.
- WindRelay is being used alongside the SpyNote remote administration tool to steal card data and send it to attackers in real time.
- In an incident investigated by Group-IB, a fraudster impersonated a bank employee and called the victim under the pretense of a problem with their payment card.
- During the call the threat actor instructed the victim to sideload the SpyNote RAT disguised as a legitimate app and grant it Accessibility Service permissions, giving the attacker remote access to the Android device.
- To add credibility, the attacker personalized the malicious app label with the victim's name.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Group-IB has documented a new Android NFC relay malware family it calls WindRelay running alongside the SpyNote remote access trojan, in an incident where the operator arranged a loan in the victim's name and simultaneously relayed the victim's live card data to a device the criminals controlled [1][2][7]. The consequence worth noting is timing: Group-IB says the entire episode took place inside a 13-minute phone call, with transactions approved using the PIN the victim read out [11].
The sequence is unglamorous. A fraudster posing as a bank employee called about a supposed problem with the victim's payment card [3]. During the call the victim was walked through sideloading SpyNote, disguised as a legitimate app, and granting it Accessibility Service permissions, which handed the attacker remote control of the handset [4]. BleepingComputer reports the app label was personalised with the victim's name; Malwarebytes describes the same app as carrying the bank's name [5][6]. From there the operator installed WindRelay with no further victim interaction and opened the legitimate banking app to take out the loan [7].
Then the second half of the toolkit. The victim was told to tap their physical card against the phone and enter its PIN, at which point WindRelay turned the handset into a fraudulent contactless reader and forwarded the live NFC exchange, including the card's transaction-specific authentication data, to the attacker's device [8]. That let the attacker transact at a genuine payment terminal [9], and Malwarebytes notes the receiving device can equally be held against an ATM that supports contactless withdrawal [10]. Relaying has to be live because modern contactless cards generate a unique one-time cryptogram per tap that cannot be replayed later, which is why timing sits at the centre of this fraud [12]. One call therefore produced two separate monetisation paths: borrowed funds in the victim's name and card-present spending elsewhere [25].
Two details matter more than the malware names. First, the call is the control channel, not just the lure, used to sequence the install, the tap and the PIN entry at the moments the operator needs them [13]. Second, unlike most current Android banking malware built around screen sharing and VNC, this combination let the attackers commit the fraud purely through social engineering over the phone [14]. Group-IB reads the pairing as a toolkit that supplies both device access for banking operations and a direct cash-out channel [15].
Scale so far is modest and measurable. Group-IB found almost two dozen WindRelay samples uploaded to VirusTotal between November 2025 and July 2026, talking to four command-and-control IP addresses [16], which works out to roughly two or three new samples a month across a nine-month window [24]. Targeting appears aimed at Czechia, Slovakia and Slovenia, inferred from the impersonated organisations and the languages used [17]. The access half of the kit is old and cheap: SpyNote and its SpyMax and CypherRAT variants have circulated since at least 2021, with detections rising after the source code leaked [18], and the RAT already handles bank data, Google and Facebook credentials, Authenticator codes, SMS, GPS, microphone, camera and keystrokes [19].
Watch whether the relay component detaches from this specific crew and shows up with other RATs, and whether the geographic focus widens. NFCShare, NGate, SuperCard X and RelayNFC established the ghost-tapping category; the pairing with a full RAT is what is new here [20][21]. Malwarebytes currently flags both components under NGate detection names [23]. Operator guidance remains blunt: no APKs from outside Google Play, treat unexpected NFC or Accessibility requests as hostile, and hang up on bank calls and dial back on a published number [22].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Researchers at Group-IB discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers, which they named WindRelay.
- [2]
WindRelay is being used alongside the SpyNote remote administration tool to steal card data and send it to attackers in real time.
- [3]
In an incident investigated by Group-IB, a fraudster impersonated a bank employee and called the victim under the pretense of a problem with their payment card.
- [4]
During the call the threat actor instructed the victim to sideload the SpyNote RAT disguised as a legitimate app and grant it Accessibility Service permissions, giving the attacker remote access to the Android device.
- [5]
To add credibility, the attacker personalized the malicious app label with the victim's name.
- [6]
Malwarebytes describes the victim as having been persuaded to install an Android app labelled with the bank's name, which was the SpyNote RAT.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comBill ToulasAug 12Android malware combo takes out loans and relays victims' credit cards
- malwarebytes.comAug 13New Android malware lets criminals use your bank card in real time
Additional citations
- Group-IB via Malwarebytes
- BleepingComputer
- Group-IB via BleepingComputer



