WindRelay and SpyNote RAT Combo Turns Android Into NFC Card Relay for Bank Fraud

A single phone call with a fraudster can now result, within the same session, in a loan taken out in the victim’s name and unauthorized purchases charged to their bank card. Researchers at Group-IB have uncovered a new attack scheme in which threat actors combine the SpyNote remote access trojan with a previously undocumented Android malware called WindRelay. WindRelay’s role is precise and singular: it transmits bank card data via NFC in real time to a device controlled by the attacker.
A 13-Minute Attack: How the Scheme Unfolds
In the case investigated by Group-IB, the entire attack took approximately 13 minutes from start to finish. The fraudster called the victim while impersonating a bank employee and alleged that a problem had arisen with the victim’s card. Following the caller’s instructions, the victim installed an application that concealed SpyNote within it. To lend the ruse additional credibility, the attackers named the malicious application after the victim themselves.
SpyNote Takes Control – Silently
Once SpyNote was installed, the attacker no longer needed any cooperation from the device’s owner. The trojan gained access to Android’s Accessibility Services, after which the fraudster remotely installed the second malicious payload – WindRelay – without any visible screen-sharing activity. Because screen broadcasting was never activated, security mechanisms designed to detect remote-control sessions may have failed to register the intrusion entirely. During that same session, the attacker used the victim’s banking application to take out a loan in the victim’s name.
WindRelay: Turning the Phone Into a Contactless Relay Terminal
The fraudster then asked the victim to hold their bank card against the smartphone and enter their PIN. WindRelay transformed the infected device into the functional equivalent of a contactless payment terminal. Critically, the malware did not merely read a static card number – it intercepted the live cryptographic exchange between the card’s chip and the reader, including the one-time transaction authentication data generated for that specific operation. That data was transmitted immediately over the internet to the attacker’s device.
The attacker’s device, in turn, presented itself to a real payment terminal or ATM as the victim’s genuine bank card. In effect, the card and the terminal continued to exchange authentic data – but the fraudsters’ infrastructure sat invisibly between them, relaying messages across distance. To the payment network, the transaction appeared as an ordinary contactless purchase or cash withdrawal. This principle closely resembles the Ghost Tap attack methodology. In the documented case, transactions involving the physical card appeared on the victim’s account shortly after the call ended.
WindRelay’s Permissions Reveal Its Purpose
An analysis of WindRelay’s permission requests confirms its specialization. The malware requests access to NFC, the internet, and contacts – and also seeks the DUMP permission, an unusual capability for a third-party application that grants access to system state information. The application’s own permissions additionally restrict other programs from accessing its internal components, further insulating its operations from scrutiny.
23 Samples, Four C2 Addresses, and Targets Across Central Europe
Group-IB identified 23 related WindRelay samples uploaded to VirusTotal between November 2025 and July 2026, along with four command-and-control IP addresses. The applications were disguised as organizations based in the Czech Republic, Slovakia, and Slovenia, and contained text strings in the corresponding national languages. Several samples – like SpyNote itself – were crafted specifically for individual victims and incorporated their names directly into the application.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.