SpyNote and WindRelay: the Android malware combo that empties bank accounts over a single phone call
Group-IB documents a 13-minute attack chain that installs a remote-access tool, takes out a loan, then relays the victim's contactless card to a criminal at a real payment terminal.

Key points
- Group-IB investigators found attackers pairing SpyNote, a remote-control app for Android phones, with a new tool called WindRelay to drain victims' accounts.
- The entire fraud took 13 minutes and relied on a single phone call.
- Almost two dozen WindRelay samples appeared on VirusTotal between November 2025 and July 2026, talking to four attacker-controlled servers.
- Targeting so far focuses on Czechia and Slovakia, with Slovenia also identified, based on the banks impersonated and the language used.
- Victims installed the app themselves and tapped their own bank card on the phone, so there's no software flaw to patch here.
A fraud crew is combining two pieces of Android malware to steal money in a single phone call, according to research from Group-IB first reported by BleepingComputer.
SpyNote is a remote administration tool, a program that lets someone else control your phone from a distance. WindRelay, the newer piece, turns the victim's phone into a fake card reader that beams live card data to a criminal standing at a real shop terminal. Group-IB's finding that one call can yield both a fraudulent loan and a live card relay puts this above the usual NFC-relay playbook. Our earlier look at RedHook on 12 July showed a similar pattern: Android trojans increasingly chain privilege tricks together rather than relying on a single exploit.
How does the scam work?
A caller pretending to be from the victim's bank says there's a problem with their payment card. During the call, the victim is walked through installing an app from outside the Google Play store, which is called sideloading. The icon carries the victim's own name to look legitimate.
Granting Accessibility Service permissions is the pivotal moment. That single tap hands the attacker full remote control.
From there the attacker works quietly in the background. Group-IB observed the criminal opening the real banking app and taking out a loan in the victim's name, then installing WindRelay without any further input from the victim.
The caller then asked the victim to hold their physical bank card against the back of the phone and type in their PIN, supposedly to verify the card. WindRelay used the phone's NFC chip, the short-range wireless technology behind contactless payments, to read the card and stream that data live to a second phone held by an accomplice at a shop till. That accomplice tapped their phone on a genuine payment terminal. The PIN the victim had just typed approved the transactions.
Group-IB clocked the whole sequence at 13 minutes.
Who is being targeted?
The campaign focuses on Czechia, Slovakia and Slovenia. Group-IB identified the region from the banks the attackers impersonated and the languages used in the fake apps.
Researchers found almost two dozen WindRelay samples uploaded to the malware-sharing site VirusTotal between November 2025 and July 2026. They communicated with four command-and-control servers, the machines criminals use to send instructions to infected phones.
| Detail | What Group-IB found |
|---|---|
| Malware combo | SpyNote remote-access tool plus WindRelay NFC relay |
| Attack length | 13 minutes, entirely by phone |
| Countries targeted | Czechia, Slovakia, Slovenia |
| WindRelay samples | Almost two dozen, seen Nov 2025 to Jul 2026 |
| Attacker servers | 4 command-and-control IP addresses |
Is this a new kind of attack?
The NFC relay trick isn't new. Families such as NGate and SuperCard X have used the same idea, and Group-IB's own list also includes NFCShare and RelayNFC. What stands out here is the pairing with SpyNote, which gives criminals full run of the banking app on top of the card relay. One call gets them a loan and a spending spree.
SpyNote has been circulating since at least 2021. Detections increased sharply after its source code leaked in late 2022. Beyond banking apps, it can read texts, steal Google Authenticator codes and activate the microphone and camera.
Should you worry?
Yes, if you're an Android user in central Europe, though the toolkit could spread. Don't install Android apps from links sent by a caller, even one who sounds like your bank. Stick to Google Play, and treat any app requesting NFC access or Accessibility permissions with serious suspicion.
If your bank calls with an urgent problem, hang up. Dial the number printed on the back of your card, and ask to be put through to the same case. A real bank won't ask you to tap your card on your phone.



