New 'WindRelay' NFC Malware & SpyNote RAT Combo Steals Card Data and Takes Out Loans
A new threat actor toolkit combining the **WindRelay** NFC relay malware with the **SpyNote** remote administration tool (RAT) is actively being used to commit financial fraud. This sophisticated duo enables attackers to steal credit card data in real-time and even secure loans in victims' names, all orchestrated through social engineering tactics.
Cybersecurity firm **Group-IB** has uncovered a potent new Android malware combination: **WindRelay**, an NFC relay malware, working in tandem with the **SpyNote** remote administration tool (RAT). This duo facilitates real-time credit card data theft and fraudulent loan applications.
### The Deceptive Attack Chain
The attack typically begins with a highly convincing social engineering ploy. A fraudster, impersonating a bank employee, contacts the victim about a supposed issue with their payment card. During the call, the attacker guides the victim to sideload **SpyNote**, disguised as a legitimate banking application, and grant it **Accessibility Service** permissions. This grants the attacker full remote access to the Android device.
To enhance credibility, the malicious app's label is often personalized with the victim's name, a detail designed to bypass suspicion.

Once **SpyNote** establishes remote access, the attacker covertly installs **WindRelay** without further victim interaction. Leveraging access to banking apps, the threat actor can then apply for and secure loans in the victim's name.
### NFC Relay for Direct Card Theft
A critical component of this scheme involves instructing the victim to tap their physical payment card against their compromised phone and enter their PIN. **WindRelay** then transforms the phone into a fraudulent contactless reader, relaying the live Near-Field Communication (NFC) exchange β including transaction-specific authentication data β to the attacker's device. This enables the attacker to use the stolen card data for purchases at genuine payment terminals.
**Group-IB** reports that these elaborate schemes can unfold rapidly, with fraudulent transactions often approved within a mere 13-minute phone call, relying on the PIN provided by the victim.

### A New Level of Sophistication
Researchers highlight that the combination of **SpyNote** and **WindRelay** represents a sophisticated toolkit offering both device access for banking transactions and a direct cash-out channel. Unlike many modern Android malware strains that rely on live screen sharing or VNC features, this particular mix achieves its objectives primarily through social engineering.
Android NFC malware is a growing concern, with other families like **NFCShare**, **NGate**, **SuperCard X**, and **RelayNFC** demonstrating similar capabilities. These typically involve tricking victims into installing malicious apps that request NFC access, then using social engineering to convince them to tap their cards, thereby capturing payment data for fraudulent use.
### The Resurgence of SpyNote
**SpyNote** (and its variants, **SpyMax** and **CypherRAT**) has been active since at least 2021. Detections surged in late 2022 and early 2023, following the public leak of the malware's source code. **SpyNote** is a versatile RAT capable of stealing bank data, **Facebook** and **Google** credentials, **Google Authenticator** codes, GPS tracking data, and SMS messages. It can also activate device microphones and cameras and intercept keystrokes.
**Group-IB** has identified almost two dozen **WindRelay** samples submitted to **VirusTotal** between November 2025 and July 2026, communicating with four distinct command-and-control IP addresses. Targeting appears to be concentrated in Czechia, Slovakia, and Slovenia, based on the impersonated organizations and languages used.
### Recommendations for Android Users
To mitigate risks, Android users are strongly advised to:
* Avoid installing APK packages from sources other than **Google Play** unless the publisher is known and trusted.
* Exercise extreme caution with apps requesting NFC access or other sensitive permissions.
* If contacted by your bank and asked to take urgent action, terminate the call immediately. Dial the official number listed on the bank's website and request to speak with the same support agent, if applicable. This verifies the legitimacy of the call and prevents falling victim to impersonation scams.
These measures are crucial in protecting against evolving social engineering and malware threats targeting mobile financial transactions.