
Cybersecurity researchers at Group-IB have documented a new type of Android attack that combines two malware tools to commit financial fraud entirely over the phone. The attack begins with a call from someone impersonating your bank. The caller claims there is a problem with your account and asks you to install a particular app — which is actually SpyNote, a remote access trojan, dressed up with your own name as the app label to appear credible. Once SpyNote is installed and granted Accessibility Service permissions, the attacker has full remote control of your phone without you realizing it. They then use your banking app remotely to take out a loan in your name. As a final step, they ask you to tap your payment card against the phone while entering your PIN — at which point a second piece of malware called WindRelay silently relays your card’s NFC transaction data to the attacker’s own contactless reader, allowing them to make purchases at any payment terminal. The full attack was completed in 13 minutes in one documented incident.
WindRelay represents a shift from typical Android banking malware that relies on screen mirroring. Instead, it intercepts the live NFC exchange between your card and the phone and transmits the transaction-specific authentication data over the internet in real time — bypassing the card’s chip protections because a legitimate PIN entry is used. Group-IB identified nearly two dozen WindRelay samples on VirusTotal submitted between November 2025 and July 2026. The malware has been primarily targeting victims in Czechia, Slovakia, and Slovenia based on the organizations impersonated and languages used, though NFC relay techniques are spreading across multiple threat actor groups globally. Other Android NFC relay families — NGate, SuperCard X, NFCShare — have been observed using similar tactics.
How to check if you’re affected
Affected devices are Android phones on which an app was installed from outside Google Play (an APK file) at the request of someone calling from a bank, tech-support line, or similar service. Check your installed apps for anything unfamiliar or anything that has Accessibility Service permissions enabled (Settings → Accessibility → Downloaded apps). If you granted NFC access to an app you didn’t choose yourself, uninstall it immediately and contact your bank. As a general rule, never install apps sent to you by someone over the phone — legitimate banks do not ask customers to sideload APK files.
