A newly identified Android fraud campaign is using the SpyNote remote-access trojan alongside a previously unseen NFC relay malware family called WindRelay to steal funds from bank customers in minutes. Group-IB said attackers impersonated bank employees in live phone calls, persuaded victims in Czechia, Slovakia, and Slovenia to sideload a malicious app, and abused Android Accessibility features to take control of the device and the victim’s banking app. In one investigated case, the criminals issued a loan in the victim’s name and began fraudulent activity within 13 minutes.
After gaining access, the attackers remotely installed WindRelay and instructed the victim to tap their physical payment card against the phone. The malware captured live NFC card data and a one-time transaction code, then relayed the exchange in real time to a second attacker-controlled device used at a legitimate payment terminal, enabling fraudulent card-present purchases without relying on stolen static card details. Group-IB linked the activity to 23 VirusTotal samples uploaded between November 2025 and July 2026 and said the operation shows how social engineering, sideloaded apps, and live NFC relaying can accelerate account takeover and payment fraud while evading ordinary checks.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Group-IB linked WindRelay to 23 malware samples uploaded to VirusTotal between November 2025 and July 2026. The samples impersonated institutions in Czechia, Slovakia, and Slovenia.
Group-IB said it first detected the previously unseen Android NFC relay malware family WindRelay in late August 2025. The malware was observed being used alongside SpyNote in contactless payment fraud schemes.
Group-IB said Czech Police arrested a 22-year-old suspect in Prague after reports of ATM withdrawals carried out without a physical card. The arrest was described as part of earlier NFC relay fraud activity in the Czech Republic.
Kaspersky says the first documented attacks using a criminally modified version of the NFCGate NFC research tool occurred in the Czech Republic in late 2023. The attacks marked an early real-world use of NFC relay malware for financial theft.
During its investigation, Group-IB identified the pairing of SpyNote RAT with the newly tracked WindRelay NFC relay malware and reported campaigns targeting users in Czechia, Slovakia, and Slovenia. The reporting also disclosed indicators including WindRelay command-and-control IPs and malware sample hashes.
After physical card charges appeared on the victim's account, the bank confirmed that NFC relay activity had occurred. This validated that the attackers had used relayed live chip-card communication rather than stolen static card details.
In a documented case, a caller posing as a bank employee convinced a victim to sideload a SpyNote-based Android app, then remotely installed WindRelay, used the victim's banking app to obtain a loan, and relayed live NFC card data for fraudulent card-present purchases. Group-IB said the loan fraud and card abuse were completed within 13 minutes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 55 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
12 references tracked. Mallory keeps watching after this page renders.
zimperium.com
Open sourceblog.knowbe4.com
Open sourcecommunity.gurucul.com
Open sourcehelpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcegroup-ib.com
Open sourcekaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.