A newly identified Android NFC relay malware called WindRelay is being deployed alongside the SpyNote remote access trojan to commit real-time financial fraud. In an incident documented by Group-IB, attackers impersonated a bank employee, convinced a victim to sideload SpyNote disguised as a legitimate app, gained Accessibility Service permissions for remote device control, then installed WindRelay without further victim interaction to take out a loan in the victim's name. The victim was also tricked into tapping their payment card and entering their PIN, letting WindRelay relay the live NFC exchange to the attacker's device for use at a real payment terminal. The whole scam took 13 minutes over a phone call. Group-IB found nearly two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026, targeting mainly Czechia, Slovakia, and Slovenia. This adds to a growing family of Android NFC relay malware including NFCShare, NGate, SuperCard X, and RelayNFC.

4m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:

Questions this post answers

What is WindRelay Android malware and how does it work with SpyNote?

WindRelay is an Android NFC relay malware that turns an infected phone into a fraudulent contactless card reader, capturing live NFC data including transaction-specific authentication codes and relaying it to an attacker's device for use at a real payment terminal. It is deployed alongside the SpyNote remote access trojan, which attackers use to gain Accessibility Service permissions and install WindRelay without further victim interaction, then take out loans through banking apps. Security teams tracking new mobile fraud techniques like NFC relay attacks can follow the latest coverage on daily.dev.

Which countries are being targeted by the WindRelay NFC malware?

Targeting appears focused on Czechia, Slovakia, and Slovenia, based on the organizations impersonated and the languages used in the fraudulent calls. Group-IB identified almost two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026, communicating with four command-and-control IP addresses. Anyone monitoring regional malware campaigns can keep an eye on emerging NFC fraud trends via daily.dev.

How can I protect myself from Android NFC relay scams involving fake bank calls?

Avoid sideloading APK packages from outside Google Play unless the publisher is known and trusted, and be cautious of apps requesting NFC access or other dangerous permissions. If someone claiming to be from a bank calls asking for urgent action, hang up and call back using the number listed on the bank's official website, then ask to be connected to the same agent. Developers building anti-fraud defenses can stay current on social engineering tactics targeting mobile users through daily.dev.

111 Impressions