Android Malware Pair Enables Loan Fraud and Live Contactless Card Relays
Cybercriminals are combining the SpyNote Android remote-access trojan with a newer NFC relay malware, WindRelay, to take control of victims’ phones, apply for loans, and use payment cards in fraudulen...
Cybercriminals are combining the SpyNote Android remote-access trojan with a newer NFC relay malware, WindRelay, to take control of victims’ phones, apply for loans, and use payment cards in fraudulent transactions.
Group-IB investigated an incident in which an attacker posed as a bank employee and contacted the victim about an alleged card problem. The victim was persuaded to install a malicious application outside Google Play and grant it Android Accessibility Service access. The application was customized with the victim’s name, helping make the call appear legitimate.
Once SpyNote provided remote access, the attacker installed WindRelay without requiring additional action from the victim. The victim was then told to place a payment card against the smartphone and enter its PIN. WindRelay reportedly used the phone’s NFC hardware to capture and forward the live communication between the card and the device to an attacker-controlled phone. This allowed the attacker to use the relayed card session at a genuine contactless payment terminal.
During the same 13-minute call, the attacker allegedly accessed the victim’s banking application and obtained a loan in the victim’s name. Group-IB said the resulting transactions were authorized with the PIN supplied during the social-engineering exchange.
Growing NFC relay threat
Researchers said the pairing of SpyNote and WindRelay gives criminals both remote access for banking fraud and a direct way to monetize stolen card interactions. Similar Android NFC malware families include NFCShare, NGate, SuperCard X, and RelayNFC. These threats typically depend on convincing victims to install an untrusted application, approve sensitive permissions, and tap a payment card on the compromised phone.
SpyNote, along with related variants such as SpyMax and CypherRAT, has been available for years and can steal credentials, SMS messages, authentication codes, location data, and keystrokes. It may also provide access to a device’s camera and microphone.
Group-IB identified nearly two dozen WindRelay samples uploaded to VirusTotal between November 2025 and July 2026. The samples contacted four command-and-control addresses, with apparent targeting centered on Czechia, Slovakia, and Slovenia.
Recommended precautions
- Avoid installing Android APK files from sources you do not trust.
- Be cautious with apps requesting NFC, Accessibility, or other high-risk permissions.
- If someone claiming to represent your bank calls with an urgent request, hang up and contact the institution using its official number.
