The phone rings. Someone claims to be from your bank and warns you of a problem with your card. They ask you to install an app to verify your identity — the app comes personalised with your name, making it look legitimate. Thirteen minutes later, the attacker has taken out a loan in your name and used your credit card at a physical payment terminal miles away, while you had your phone in your hand.

This is not a hypothetical scenario. It is the case documented by Group-IB in August 2026, describing the combination of two Android malware tools — SpyNote and WindRelay — operating in tandem to execute complete bank fraud from a single phone call.

Imagen del artículo

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

Two malware tools, one objective

SpyNote is an Android remote access trojan (RAT) active since 2021, whose popularity among attackers surged in 2023 after its source code was leaked. Once installed on the victim's device with Accessibility Service permissions granted, it gives the attacker full control over the phone: they can see the screen in real time, launch applications, intercept SMS messages, activate the microphone and camera, and capture keystrokes.

WindRelay is more recent and more specific: it turns the phone into a fraudulent NFC reader. When the victim taps a payment card against the phone and enters their PIN, WindRelay captures the transaction authentication data and relays it in real time to the attacker's device. The attacker uses that data at a real payment terminal, as if they had the physical card in their hand.

The combination is more dangerous than either malware individually. SpyNote provides remote access to install WindRelay without further victim interaction and to operate the banking apps on the device. WindRelay provides the direct cash-out channel via NFC. Together, they cover both access to the bank account and extraction of funds.

How the attack works step by step

The attacker calls the victim posing as a bank employee and claims there is a problem with their payment card. To add credibility, they have generated a version of SpyNote with the victim's name in the app label — attackers use an automated builder that creates personalised APKs per target.

During the call, they convince the victim to install the application outside Google Play — sideloading — and to grant it Accessibility Service permissions. With that, the attacker has full remote access to the device. They install WindRelay without further victim interaction, access the installed banking apps, and take out a loan in the victim's name.

They then instruct the victim to tap their credit card against the phone and enter their PIN. WindRelay captures the NFC exchange including the transaction-specific authentication data and relays it to the attacker's device. Transactions are approved using the PIN the victim just entered.

Total time from the first call to completed fraud: 13 minutes.

Why NFC relay attacks are particularly hard to detect

NFC relay attacks do not require cloning the card or obtaining the static chip data. They relay the communication session in real time between the real card and the attacker's terminal. From the payment terminal's perspective, the transaction looks entirely legitimate — the authentication data is valid because it corresponds to a real session with the victim's actual card.

Android NFC relay malware is not new — families such as NGate, SuperCard X and NFCShare have been active for several years — but combining it with a RAT like SpyNote that provides full remote device access adds a layer of sophistication: the attacker doesn't need to trick the victim into doing anything beyond installing the first app. Everything else they do themselves from another device.

If you receive a call like this

Don't do this:

Do this:

A legitimate app from your bank is not installed on the instruction of an inbound call. A bank's real support channel never requires you to install anything outside their official app or to tap your card against your phone during a phone conversation.