Android Malware Combo Uses SpyNote and WindRelay to Steal Card Data and Take Out Loans
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote access trojan (RAT) to steal payment card data and relay contactless transactions to cybercriminals in real time.
According to cybersecurity firm Group-IB, attackers in one investigated campaign impersonated bank employees and called victims while claiming there was a problem with their payment cards.
During the phone call, the fraudsters persuaded victims to sideload SpyNote, disguised as a legitimate Android application. The attackers then instructed victims to grant the app Android accessibility service permissions, giving them remote control over the compromised device.
To make the malicious application appear more credible, the attackers customized its label using the victim’s name.

Source: Group-IB
Once SpyNote provided remote access to the Android device, the attacker installed WindRelay without requiring additional action from the victim. The attacker then used the victim’s banking application to apply for a loan in the victim’s name.
The victim was subsequently instructed to tap their payment card against the smartphone and enter their card PIN. WindRelay turned the Android phone into a malicious contactless card reader and relayed a live NFC, or near-field communication, exchange to the attacker’s device.
The relayed exchange included transaction-specific authentication data, allowing the attacker to use the payment card at legitimate point-of-sale terminals.
Group-IB said the complete attack took place during a 13-minute phone call. The fraudulent transaction was approved using the PIN supplied by the victim.

Source: Group-IB
Researchers said the combination of SpyNote and WindRelay could provide criminals with both persistent access to victims’ Android devices and a direct method for conducting fraudulent payment transactions.
Unlike many modern Android malware families that rely on live screen sharing or virtual network computing (VNC), this attack chain allowed criminals to carry out the fraud primarily through telephone-based social engineering.
Android NFC relay malware has become an increasing threat, with other known families including NFCShare, NGate, SuperCard X, and RelayNFC.
In a typical NFC relay attack, the victim installs a malicious Android application and grants it access to NFC-related functions. The attacker then uses social engineering to convince the victim to tap a payment card against the compromised phone.
The infected device communicates with the contactless card through its NFC interface, captures available payment data, and transmits it over the internet to an attacker-controlled device.
Depending on the information captured and the attacker’s techniques, the stolen data may be used for fraudulent purchases, cash withdrawals from ATMs, or other forms of financial theft.
The SpyNote RAT and related variants, including SpyMax and CypherRAT, have been active since at least 2021. Detections increased in late 2022 and early 2023 after the malware’s source code was leaked.
SpyNote can steal online banking information, Facebook and Google credentials, Google Authenticator codes, GPS location data, and SMS messages. The malware can also activate a device’s microphone and camera and intercept common keystrokes.
Group-IB identified approximately 20 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026. The samples communicated with four command-and-control IP addresses.
Based on the organizations impersonated and the languages used by the attackers, researchers believe the campaign primarily targeted victims in the Czech Republic, Slovakia, and Slovenia.
Android users should avoid installing APK files from outside Google Play unless they know and trust the publisher. Users should also be cautious about applications requesting NFC access, accessibility services, or other high-risk permissions.
If someone claiming to represent your bank calls about an urgent account or payment-card problem, hang up and contact the bank using the official phone number listed on its website or payment card. Do not install software, reveal PINs, or grant remote-access permissions at the caller’s request.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




