SpyNote and WindRelay: the Android malware combo that empties bank accounts over a single phone call

Group-IB documents a 13-minute attack chain that installs a remote-access tool, takes out a loan, then relays the victim's contactless card to a criminal at a real payment terminal.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge 16:9 photoreal news-editorial image of a generic Android-style smartphone face-up on a dark desk, screen glowing faintly with abstract g
Share

Key points

  • Group-IB investigators found attackers pairing SpyNote, a remote-control app for Android phones, with a new tool called WindRelay to drain victims' accounts.
  • The entire fraud, from first call to card charges, took 13 minutes and relied only on a phone conversation.
  • Almost two dozen WindRelay samples appeared on VirusTotal between November 2025 and July 2026, talking to four attacker-controlled servers.
  • Targeting so far focuses on Czechia, Slovakia and Slovenia, based on the banks impersonated and the language used.
  • Victims were tricked into installing the app themselves and tapping their bank card on the phone, so no software flaw is being patched here.

A fraud crew is combining two pieces of Android malware to steal money in a single phone call, according to research from Group-IB first reported by BleepingComputer.

The first piece, SpyNote, is a remote administration tool (a program that lets someone else control your phone from a distance). The second, newly named WindRelay, turns the victim's own phone into a fake card reader that beams live card data to a criminal standing at a real shop terminal.

Here is how the attack actually plays out.

How does the scam work?

A caller pretending to be from the victim's bank says there is a problem with their payment card. During the call, the victim is walked through installing an app from outside the Google Play store, which is called sideloading. The app is dressed up with the victim's own name on the icon to look legitimate.

The victim is then asked to grant it Accessibility Service permissions. That single tap hands the attacker remote control of the phone.

From there the attacker works quietly in the background. Group-IB observed the criminal opening the real banking app and taking out a loan in the victim's name. WindRelay was then installed without the victim needing to do anything else.

Then came the clever part. The caller asked the victim to hold their physical bank card against the back of the phone and type in their PIN, supposedly to verify the card. WindRelay used the phone's NFC chip (the short-range wireless technology behind contactless payments) to read the card and stream that data, live, to a second phone held by an accomplice at a shop till.

That accomplice tapped their phone on a genuine payment terminal and paid with the victim's card. The PIN the victim had just typed approved the transactions.

Group-IB clocked the whole sequence at 13 minutes.

Who is being targeted?

The campaign so far focuses on Czechia, Slovakia and Slovenia. Group-IB identified the region from the banks the attackers impersonated and the language used in the fake apps.

Researchers found nearly two dozen WindRelay samples uploaded to the malware-sharing site VirusTotal between November 2025 and July 2026. They communicated with four command-and-control servers (the machines criminals use to send instructions to infected phones).

Detail What Group-IB found
Malware combo SpyNote remote-access tool plus WindRelay NFC relay
Attack length 13 minutes, entirely by phone
Countries targeted Czechia, Slovakia, Slovenia
WindRelay samples Almost 20, seen Nov 2025 to Jul 2026
Attacker servers 4 command-and-control IP addresses

Is this a new kind of attack?

The NFC relay trick is not new. Families such as NGate, SuperCard X and RelayNFC have used the same idea. What stands out here is the pairing with SpyNote, which gives criminals full run of the banking app on top of the card relay. In effect, one call gets them a loan and a spending spree.

SpyNote itself has been circulating since 2021 and spread faster after its source code leaked in late 2022. It can also read texts, steal Google Authenticator codes, and switch on the microphone and camera.

What should ordinary people do?

Do not install Android apps from links sent by a caller, even one who sounds like your bank. Stick to Google Play, and be wary of any app that asks for NFC access or Accessibility permissions.

If your bank calls with an urgent problem, hang up. Then dial the number printed on the back of your card or on the bank's official website, and ask to be put through to the same case. A real bank will never ask you to tap your card on your phone during a support call.

© 2026 Threat Vectr