A new Android malware strain called WindRelay is being used with the SpyNote remote administration tool to steal payment card data and relay it to attackers in real time, allowing fraudulent transactions to be carried out through genuine payment terminals.
In one case investigated by cybersecurity company Group-IB, a fraudster posed as a bank employee and called a victim claiming there was a problem with the person’s payment card. The victim was persuaded to install SpyNote, disguised as a legitimate application, and grant it Accessibility Service permissions, giving the attacker remote control of the Android device. To make the malicious application appear more convincing, the attacker even personalised its label with the victim’s name.
SpyNote Gives Attackers Remote Access to Victim’s Phone
Once remote access had been established through SpyNote, the attacker installed WindRelay without requiring further action from the victim. The attacker then used the victim’s banking application to take out a loan in the victim’s name. The victim was also instructed to tap a payment card against the compromised phone and enter the card PIN. WindRelay effectively turned the Android device into a fraudulent contactless reader. The malware captured the live NFC exchange between the card and the phone, including transaction-specific authentication data, and relayed it to a device controlled by the attacker.
That information was then used to make purchases at a genuine payment terminal. Group-IB said the entire operation took place during a 13-minute phone call, with transactions approved using the PIN supplied by the victim.
NFC Relay Malware Adds New Route for Financial Fraud
The combination of SpyNote and WindRelay gives attackers both remote access to a victim’s device and a direct way to exploit payment card data. Android NFC relay attacks typically rely heavily on social engineering. Victims are convinced to install a malicious application, grant NFC access and physically tap their payment cards against an infected phone.
The phone then communicates with the contactless card through NFC and transmits available card information over the internet to another attacker-controlled device. Depending on the information captured and the technique used, the stolen data can potentially support fraudulent transactions and other financial theft. SpyNote and related variants including SpyMax and CypherRAT have circulated since at least 2021.
WindRelay Activity Linked to Central European Targets
Group-IB identified almost two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026. The samples communicated with four command-and-control IP addresses. The targeting appears concentrated on Czechia, Slovakia and Slovenia, based on the organisations being impersonated and the languages used.
Android users are advised to avoid installing APK packages from outside Google Play unless they know and trust the publisher, and to be particularly cautious when applications request NFC access or other sensitive permissions. Users receiving urgent calls claiming to come from their bank should end the call and independently contact the institution using the number published on its official website rather than following instructions from the caller.
