Illustrative image generated with AI
SpyNote and WindRelay: the Android Attack Combining Fraudulent Loans and NFC Relay
Discover how Android users are targeted by SpyNote and WindRelay malware in a scam combining fraudulent loans and NFC relay for contactless fraud.
Text generated by artificial intelligence, published without human review. AI transparency
The Scam Starts with a Fake Bank Call
A recent Android attack analyzed by Group-IB combines the SpyNote RAT with WindRelay, malware designed to relay NFC communications. The operation was described on August 12, 2026.
The scammer contacted the victim while posing as a bank employee and reporting an issue with their card. During the 13-minute call, the victim was persuaded to sideload an APK presented as a legitimate application. The app had been personalized with the victim’s name.
The application installs SpyNote and requests access to Accessibility Service, a permission that enables extensive monitoring and control of device functions. Once remote access had been obtained, the attacker installed WindRelay without requiring any further action from the user.
SpyNote Controls the Smartphone and Banking App
SpyNote is an Android RAT known since at least 2021. Reported variants include SpyMax and CypherRAT; detections increased between late 2022 and early 2023 after the source code was published.
The malware can steal:
- banking data and credentials;
- Facebook and Google accounts;
- Google Authenticator codes;
- SMS messages and keystrokes;
- GPS location data.
It can also activate the microphone and camera. In the incident analyzed, remote access enabled the criminal to use the victim’s banking app to apply for a loan in their name.
The exact versions of the components used in the attack have not been disclosed.
WindRelay Turns the Phone into a Contactless Relay
The second stage uses WindRelay. The malware allows the compromised smartphone to communicate with a payment card held near the victim, forwarding the data exchanged over NFC to the attacker’s device in real time.
The flow also includes transaction-specific authentication data. The attacker can therefore use the information received at a real payment terminal while directing the victim toward the phone and obtaining their PIN.
The relay can be difficult to detect: the card remains near the victim’s smartphone, while the attacker’s device acts as the remote counterpart. The observed transactions were authorized using the PIN provided by the victim.
The technique could be reused for other types of fraud or, under certain conditions, for ATM withdrawals. Its feasibility depends on the data obtained and the procedure used.
Samples and Targeting
Group-IB identified nearly two dozen WindRelay samples uploaded to VirusTotal between November 2025 and July 2026. The samples communicated with four command-and-control IP addresses.
The targeting appears to focus on Czechia, Slovakia, and Slovenia, based on the organizations impersonated and the languages used during the calls. WindRelay is part of a broader sequence of NFC malware that also includes NFCShare, NGate, SuperCard X, and RelayNFC.
Combining it with SpyNote expands the criminal model: the same access enables attackers to control the device, operate banking services, and directly monetize NFC data. The attack does not necessarily require screen sharing or VNC.
How to Reduce the Risk
- Prefer installing applications from Google Play rather than from APKs received during calls or via messages.
- Do not grant Accessibility Service access to apps whose origin or purpose is uncertain.
- Pay particular attention to requests for NFC access and other high-risk permissions.
- End banking calls that create a sense of urgency or provide unusual instructions.
- Call the bank back using the number published on its official website.
- Never disclose your card PIN over the phone.
- Do not hold your card near your phone or authorize transactions in response to unverified instructions.
Sources
This article is an original reworking based on the sources below.
