# WindRelay + SpyNote Combo: NFC Relay Malware Enables Contactless Card Fraud Across Central/Eastern Europe

> Group-IB documents WindRelay, a newly tracked purpose-built Android NFC relay tool, deployed alongside the SpyNote RAT in a vishing-driven fraud scheme. Fraudsters posing as bank employees talk victims into sideloading a personalized SpyNote APK, then abuse its Accessibility Service access to silently install WindRelay, which relays live contactless card data to attacker-controlled devices for card-present purchases and ATM cash-outs, alongside fraudulent digital loans issued via banking-app takeover.

- **Published:** 2026-08-12T00:00:00Z
- **Last reviewed:** 2026-08-12T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1995
- **ID:** TL-2026-1995
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Group-IB's Fraud Protection team documented a two-malware Android fraud combo active across Central and Eastern Europe since at least November 2025. The scheme begins with a phone call in which the fraudster impersonates a bank employee and claims a problem with the victim's card, then walks the victim through installing an Android APK during the live call. That first-stage app is a personalized variant of the SpyNote RAT — the application label is set to the victim's own name, a deliberate trust-abuse tactic intended to lower suspicion since victims believe they are installing something sanctioned by their bank. SpyNote requests Accessibility Service permission, which it then abuses to silently sideload a second payload, WindRelay, via the device's package installer without triggering a visible screen-share prompt or requiring further victim interaction. WindRelay is Group-IB's newly tracked name for a purpose-built NFC relay tool: once installed, it instructs the victim (still on the phone with the fraudster) to tap their physical contactless payment card to their own handset and enter their PIN. WindRelay reads the live EMV contactless handshake off the NFC chip and streams it in real time over the internet to a second, attacker-controlled Android device, which replays the exchange at a real merchant POS terminal or ATM as if the victim's card were physically present, PIN included. In parallel, SpyNote's remote-control and Accessibility Service access is used to navigate the victim's mobile banking app and issue a fraudulent digital loan in the victim's name — a second monetization path pursued in the same call. Group-IB reports the entire sequence, from the first malicious install through the NFC capture and loan issuance, completes in as little as 13 minutes, well inside the window in which a victim could contact their bank to intervene. The operation has hit victims across Czechia, Slovakia, Slovenia, and Poland; Group-IB attributes the campaign via metadata correlation across 23 WindRelay and 7 SpyNote samples collected between November 2025 and July 2026, alongside 4 shared C2 IP addresses. Group-IB frames the technique as part of a broader, fast-growing NFC relay threat class: Kaspersky separately reported a 188% year-over-year increase in NFC-relay-style Android malware detections (35,600 blocked attacks January-April 2026 versus over 12,300 in the same period of 2025, across families including SuperCard X, PhantomCard, NGate, and modified NFCGate variants), and Group-IB's own prior research on 'Ghost Tap'/TX-NFC-style HCE card-emulation fraud documents a related but architecturally distinct NFC abuse pattern (relay app runs on the fraudster's device using stolen card credentials rather than live-relaying from the victim's phone) that has produced at least $355,000 in documented losses from a single point-of-sale vendor between November 2024 and August 2025.

## MITRE ATT&CK

- T1660 Phishing
- T1407 Download New Code at Runtime
- T1624.001 Broadcast Receivers
- T1453 Abuse Accessibility Features
- T1417 Input Capture
- T1636.003 Contact List
- T1638 Adversary-in-the-Middle
- T1418 Software Discovery
- T1663 Remote Access Software
- T1646 Exfiltration Over C2 Channel
- T1516 Input Injection
- T1657 Financial Theft

## Sources

- [Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme](https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/)
- [WindRelay Turns Android Phones Into Fake Payment Terminals for Remote Card Fraud](https://gbhackers.com/windrelay-turns-android-phones/)
- [13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts](https://cybersecuritynews.com/13-minute-windrelay-malware-attack/)
- [NFC relay attacks on smartphones surged by 188% in 2026, Kaspersky reveals](https://me-en.kaspersky.com/about/press-releases/nfc-relay-attacks-on-smartphones-surged-by-188-in-2026-kaspersky-reveals)
- [Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android Malware](https://www.group-ib.com/blog/ghost-tapped-chinese-malware/)
- [TX-NFC (Ghost Tap): NFC Relay Fraud Threat Profile](https://www.group-ib.com/masked-actors/tx-nfc/)
- [SpyNote RAT, Software S0305](https://attack.mitre.org/software/S0305/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1995
