A new Android malware combination, featuring the WindRelay NFC relay tool and the SpyNote remote administration tool (RAT), has been observed by cybersecurity firm Group-IB in attacks designed to steal credit card data and facilitate fraudulent loans. This sophisticated toolkit allows attackers to gain remote control over a victim's device and relay live NFC payment card exchanges, including transaction-specific authentication data.
In a specific incident investigated by Group-IB, a fraudster impersonated a bank employee and contacted a victim, claiming there was an issue with their payment card. During the call, the attacker instructed the victim to sideload a malicious SpyNote RAT application, disguised as a legitimate bank app and personalized with the victim's name. The victim was then prompted to grant Accessibility Service permissions, which provided the attacker with remote access to the Android device.
Once SpyNote was installed and access was established, the attacker remotely installed WindRelay without further interaction from the victim. The attacker then used the victim's banking app to take out a loan in their name. Additionally, the victim was instructed to tap their payment card against the phone and enter their PIN. WindRelay transformed the phone into a fraudulent contactless reader, relaying the live NFC exchange, including the card's transaction-specific authentication data, to the attacker's device. This enabled the attacker to use the stolen card data for purchases at a genuine payment terminal. Group-IB reported that the entire fraudulent activity, including the loan and card transactions, occurred within a 13-minute phone call, with transactions approved using the PIN provided by the victim.
The researchers note that this combination of SpyNote and WindRelay suggests a comprehensive toolkit for attackers, providing both remote access for banking transactions and a direct channel for cashing out. Unlike many modern Android malware strains that rely on live screen sharing or VNC features, this particular attack chain achieved its objectives primarily through social engineering conducted over the phone.
Android NFC malware is an increasing concern, with other families like NFCShare, NGate, SuperCard X, and RelayNFC demonstrating similar capabilities. Typically, these attacks involve the victim installing a malicious app and granting it NFC access. Attackers then socially engineer victims into tapping their payment cards against the compromised phone, which captures and transmits the card data to an attacker-controlled device for fraudulent use or financial theft.
The SpyNote RAT and its variants, such as SpyMax and CypherRAT, have been active since at least 2021. Detections of these RATs saw a notable increase in late 2022 and early 2023, following the public leak of the malware's source code. SpyNote is capable of stealing banking information, Facebook and Google account credentials, Google Authenticator codes, GPS tracking data, and SMS messages. It can also activate the device microphone and camera, and intercept keystrokes.
Group-IB has identified nearly two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026. These samples communicated with four distinct command-and-control IP addresses. Based on the organizations impersonated and the languages used in the attacks, targeting appears to be concentrated in Czechia, Slovakia, and Slovenia.
To mitigate such threats, Android users are strongly advised to avoid installing APK packages from sources other than Google Play, unless they have complete trust in the publisher. Extreme caution should be exercised with any app that requests NFC access or other potentially dangerous permissions. If contacted by a bank and asked to take urgent action, it is recommended to end the call, dial the official number listed on the bank's website, and request to speak with the same support agent.






