A newly identified Android fraud campaign is using the SpyNote remote-access trojan alongside a previously unseen NFC relay malware family called WindRelay to steal funds from bank customers in minutes. Group-IB said attackers impersonated bank employees in live phone calls, persuaded victims in Czechia, Slovakia, and Slovenia to sideload a malicious app, and abused Android Accessibility features to take control of the device and the victim’s banking app. In one investigated case, the criminals issued a loan in the victim’s name and began fraudulent activity within 13 minutes.
After gaining access, the attackers remotely installed WindRelay and instructed the victim to tap their physical payment card against the phone. The malware captured live NFC card data and a one-time transaction code, then relayed the exchange in real time to a second attacker-controlled device used at a legitimate payment terminal, enabling fraudulent card-present purchases without relying on stolen static card details. Group-IB linked the activity to 23 VirusTotal samples uploaded between November 2025 and July 2026 and said the operation shows how social engineering, sideloaded apps, and live NFC relaying can accelerate account takeover and payment fraud while evading ordinary checks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Group-IB linked WindRelay to 23 malware samples uploaded to VirusTotal between November 2025 and July 2026. The samples impersonated institutions in Czechia, Slovakia, and Slovenia.
Group-IB said Czech Police arrested a 22-year-old suspect in Prague after reports of ATM withdrawals carried out without a physical card. The arrest was described as part of earlier NFC relay fraud activity in the Czech Republic.
Kaspersky says the first documented attacks using a criminally modified version of the NFCGate NFC research tool occurred in the Czech Republic in late 2023. The attacks marked an early real-world use of NFC relay malware for financial theft.
During its investigation, Group-IB identified the pairing of SpyNote RAT with the newly tracked WindRelay NFC relay malware and reported campaigns targeting users in Czechia, Slovakia, and Slovenia. The reporting also disclosed indicators including WindRelay command-and-control IPs and malware sample hashes.
After physical card charges appeared on the victim's account, the bank confirmed that NFC relay activity had occurred. This validated that the attackers had used relayed live chip-card communication rather than stolen static card details.
In a documented case, a caller posing as a bank employee convinced a victim to sideload a SpyNote-based Android app, then remotely installed WindRelay, used the victim's banking app to obtain a loan, and relayed live NFC card data for fraudulent card-present purchases. Group-IB said the loan fraud and card abuse were completed within 13 minutes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcemalware.news
Open sourcebleepingcomputer.com
Open sourceinfosecurity-magazine.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcegroup-ib.com
Open sourcekaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.