Threat reportMalwareTL-2026-2003
WindRelay Android NFC Relay Malware Paired With SpyNote RAT Enables Real-Time Bank Card "Ghost Tapping" Fraud
WindRelay Android NFC Relay Malware Paired With SpyNote RAT (TL-2026-2003), also tracked as Ghost Tap, is a high-severity malware campaign, first published 2026-08-13. It has no confirmed attribution, affects Google Android, maps to 10 MITRE ATT&CK techniques (T1418.001, T1437, T1516), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-2003
- Threat ID
- TL-2026-2003
- Also known as
- Ghost Tap, Ghost Tapping
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, banking, consumer
- Target regions
- czechia, slovakia, slovenia, Europe
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in WindRelay Android NFC Relay Malware Paired With SpyNote RAT
Malware and tooling: Android/Trojan.NGate.ACR2401245FC5, Android/Trojan.NGate.ACRBCF9BBC3C1, NGate, SpyNote, SpyNote RAT - S0305, SuperCard X, WindRelay
How WindRelay Android NFC Relay Malware Paired With SpyNote RAT works
WindRelay is a newly documented Android NFC-relay malware, deployed alongside a SpyNote remote access trojan variant, that captures a victim's live contactless card exchange -- including one-time transaction authentication codes -- and relays it in real time to a criminal-controlled device held against a payment terminal or ATM. Group-IB documented a case in which a vished victim was walked through a 13-minute phone call that resulted in an unauthorized loan and fraudulent NFC-relayed card transactions, part of a set of 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026 that predominantly impersonate financial institutions in Czechia, Slovakia, and Slovenia.
WindRelay is an NFC relay ('ghost tapping') malware family for Android, first publicly documented by Group-IB on 2026-08-12 in the report "Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme," and independently covered the following day by Malwarebytes. It is deployed as the second stage of a two-malware combo alongside a variant of SpyNote, a long-running, source-code-leaked (2020, v6.4) Android remote access trojan with banking-overlay and full device-control capabilities that has since been commercialized and forked widely (e.g., the CypherRat/SpyNote.C variant sold via Telegram 2021-2022).
The infection chain begins with vishing: a fraudster calls the victim impersonating bank staff, claiming a problem with their card. In Group-IB's documented case study, the entire compromise -- from the opening pretext to fraudulent transaction -- took just 13 minutes, with the live call itself doubling as a real-time control channel the attacker used to talk the victim through each step and defeat hesitation. The victim is guided to sideload a personalized APK (labeled with the victim's own name, indicating prior reconnaissance) that installs SpyNote outside the Play Store. SpyNote abuses Android's Accessibility Service to grant itself the ability to silently install additional packages without further user interaction, and uses this access to sideload WindRelay mid-call. WindRelay requests NFC, INTERNET, READ_CONTACTS, and DUMP permissions -- the last used to detect security tooling on the device, and READ_CONTACTS to harvest further victim leads. The attacker then instructs the victim to tap their payment card against their own (compromised) phone; WindRelay turns the device into a rogue contactless reader, capturing the live chip-to-reader exchange -- including the card's single-use, transaction-specific cryptographic authentication data -- and streaming it over the internet in real time to a second, attacker-held device that presents it to a genuine POS terminal or NFC-enabled ATM. Because the relay happens live, the receiving terminal sees what looks like an ordinary, valid tap, defeating the replay protection that dynamic per-transaction codes are designed to provide. In the observed case, attackers additionally used the RAT's access to the victim's banking app to originate a fraudulent loan in parallel with the card fraud.
Group-IB identified 23 WindRelay samples submitted to VirusTotal between November 2025 and July 2026, alongside 7 related SpyNote samples, communicating with four command-and-control IP addresses. Targeting -- inferred from impersonated-institution branding and in-app language -- centers on Czechia, Slovakia, and Slovenia. No specific threat actor or nation-state attribution was published for this campaign.
WindRelay is the latest entrant in an NFC-relay malware lineage that Group-IB and others track as "Ghost Tapping" or "Ghost Tap": ESET first documented the technique in the wild as NGate, targeting Czech bank customers from late November 2023 and escalating to a dedicated Android malware by March 2024 (leading to the arrest of a 22-year-old suspect in Prague carrying over $6,500 in stolen cash); Cleafy documented SuperCard X in April 2025, a Chinese-speaking-operated NFC-relay malware-as-a-service targeting Italian bank and card-issuer customers via smishing/vishing. Group-IB separately tracks the broader Chinese-language fraud-as-a-service ecosystem behind this technique class as "TX-NFC," noting NFC-based attacks on Android rose 188% in the first four months of 2026 versus the same period in 2025 (35,600 attacks blocked). WindRelay's distinguishing feature versus this lineage is its tight coupling with a live-call-controlled RAT (SpyNote) for real-time victim manipulation and parallel loan fraud, rather than NFC relay alone.
MITRE ATT&CK techniques used in TL-2026-2003
Discovery
T1418.001 Security Software Discovery
Command and Control
T1437 Application Layer Protocol; T1663 Remote Access Software
Impact
Collection
T1533 Data from Local System; T1636.003 Contact List
collection
Exfiltration
T1646 Exfiltration Over C2 Channel
defense-evasion
Initial Access
Affected products and versions in WindRelay Android NFC Relay Malware Paired With SpyNote RAT
- Google — Android
Vulnerable versions: NFC/Host Card Emulation-capable Android devices, all supported versions (technique abuses legitimate NFC/Accessibility Service functionality, not a code vulnerability)
Remediation for WindRelay Android NFC Relay Malware Paired With SpyNote RAT
Immediate actions
- Treat any customer-facing request to install an application or tap a payment card against a phone during an unsolicited, inbound bank-support phone call as a compromise indicator and terminate the session
- Hold or manually review any loan disbursement that co-occurs with a near-simultaneous physical card/POS or ATM transaction on the same account
- Block sideloaded (non-Play-Store) application installs that request the NFC + INTERNET + READ_CONTACTS + DUMP permission combination on banking-related devices where such controls are available
Workarounds
- Educate customers that legitimate banks never ask them to install an application or tap their payment card against their own phone during an unsolicited support call
- Instruct customers to hang up and independently call their bank's officially published number whenever contacted about a card or account problem
Longer-term hardening
- Deploy mobile fraud-prevention tooling capable of detecting sideloaded APK installation and Accessibility Service permission grants that occur while an active phone call is in progress
- Build detection logic on the co-occurrence of NFC, INTERNET, READ_CONTACTS, and DUMP permission grants on newly installed, non-official-store Android applications
- Apply step-up authentication for loan originations and high-value transactions when an active-call or recent-sideload signal is present on the originating device
Timeline of WindRelay Android NFC Relay Malware Paired With SpyNote RAT
- ESET Research first observes a threat actor targeting customers of three major Czech banks with the NFC-relay fraud technique that would become NGate, the earliest documented ancestor of the WindRelay/Ghost Tapping malware lineage.
- The Czech NFC-relay campaign escalates to deployment of the dedicated NGate Android malware, which clones and relays NFC payment card data to ATMs for cash withdrawal; Czech police arrest a 22-year-old suspect in Prague found carrying over $6,500 in stolen cash.
- Cleafy documents SuperCard X, a Chinese-speaking-operated NFC-relay malware-as-a-service combining smishing/vishing with NFC card data interception, targeting Italian banking and card-issuer customers -- establishing the malware-as-a-service model within the Ghost Tapping family.
- The earliest WindRelay sample in Group-IB's later-published dataset is submitted to VirusTotal, opening the November 2025-July 2026 collection window Group-IB used to identify 23 related WindRelay samples.
- The most recent WindRelay sample in Group-IB's 23-sample VirusTotal dataset is submitted, closing the observed November 2025-July 2026 collection window.
- Group-IB publishes "Gone with the WindRelay," the first public technical disclosure of the WindRelay NFC-relay malware paired with a SpyNote RAT variant, including a case study in which a fraudulent 13-minute bank-impersonation phone call resulted in an unauthorized loan and live NFC-relayed card transactions, targeting victims in Czechia, Slovakia, and Slovenia.
- Malwarebytes and other outlets, including BleepingComputer and Infosecurity Magazine, publish coverage summarizing the WindRelay/SpyNote campaign, flagging samples as Android/Trojan.NGate.ACRBCF9BBC3C1 and Android/Trojan.NGate.ACR2401245FC5.
Sources cited for WindRelay Android NFC Relay Malware Paired With SpyNote RAT
- New Android malware lets criminals use your bank card in real time
- Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
- Android malware combo takes out loans and relays victims' credit cards
- WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam
- TX-NFC (Ghost Tap): NFC Relay Fraud Threat Profile
- ESET Research discovers NGate: Android malware, which relays NFC traffic to steal victim's cash from ATMs
- SuperCard X: exposing a Chinese-speaker MaaS for NFC Relay fraud operation
- SuperCard X Android Malware Enables Contactless ATM and PoS Fraud via NFC Relay Attacks
Detection coverage for TL-2026-2003
As of 2026-08-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2003 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.