Threat reportMalwareTL-2026-2003

WindRelay Android NFC Relay Malware Paired With SpyNote RAT Enables Real-Time Bank Card "Ghost Tapping" Fraud

highACTIVE

WindRelay Android NFC Relay Malware Paired With SpyNote RAT (TL-2026-2003), also tracked as Ghost Tap, is a high-severity malware campaign, first published 2026-08-13. It has no confirmed attribution, affects Google Android, maps to 10 MITRE ATT&CK techniques (T1418.001, T1437, T1516), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-2003

Threat ID
TL-2026-2003
Also known as
Ghost Tap, Ghost Tapping
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, banking, consumer
Target regions
czechia, slovakia, slovenia, Europe
Detection rules
9
Indicators of compromise
15

Malware and tooling in WindRelay Android NFC Relay Malware Paired With SpyNote RAT

Malware and tooling: Android/Trojan.NGate.ACR2401245FC5, Android/Trojan.NGate.ACRBCF9BBC3C1, NGate, SpyNote, SpyNote RAT - S0305, SuperCard X, WindRelay

How WindRelay Android NFC Relay Malware Paired With SpyNote RAT works

WindRelay is a newly documented Android NFC-relay malware, deployed alongside a SpyNote remote access trojan variant, that captures a victim's live contactless card exchange -- including one-time transaction authentication codes -- and relays it in real time to a criminal-controlled device held against a payment terminal or ATM. Group-IB documented a case in which a vished victim was walked through a 13-minute phone call that resulted in an unauthorized loan and fraudulent NFC-relayed card transactions, part of a set of 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026 that predominantly impersonate financial institutions in Czechia, Slovakia, and Slovenia.

WindRelay is an NFC relay ('ghost tapping') malware family for Android, first publicly documented by Group-IB on 2026-08-12 in the report "Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme," and independently covered the following day by Malwarebytes. It is deployed as the second stage of a two-malware combo alongside a variant of SpyNote, a long-running, source-code-leaked (2020, v6.4) Android remote access trojan with banking-overlay and full device-control capabilities that has since been commercialized and forked widely (e.g., the CypherRat/SpyNote.C variant sold via Telegram 2021-2022).

The infection chain begins with vishing: a fraudster calls the victim impersonating bank staff, claiming a problem with their card. In Group-IB's documented case study, the entire compromise -- from the opening pretext to fraudulent transaction -- took just 13 minutes, with the live call itself doubling as a real-time control channel the attacker used to talk the victim through each step and defeat hesitation. The victim is guided to sideload a personalized APK (labeled with the victim's own name, indicating prior reconnaissance) that installs SpyNote outside the Play Store. SpyNote abuses Android's Accessibility Service to grant itself the ability to silently install additional packages without further user interaction, and uses this access to sideload WindRelay mid-call. WindRelay requests NFC, INTERNET, READ_CONTACTS, and DUMP permissions -- the last used to detect security tooling on the device, and READ_CONTACTS to harvest further victim leads. The attacker then instructs the victim to tap their payment card against their own (compromised) phone; WindRelay turns the device into a rogue contactless reader, capturing the live chip-to-reader exchange -- including the card's single-use, transaction-specific cryptographic authentication data -- and streaming it over the internet in real time to a second, attacker-held device that presents it to a genuine POS terminal or NFC-enabled ATM. Because the relay happens live, the receiving terminal sees what looks like an ordinary, valid tap, defeating the replay protection that dynamic per-transaction codes are designed to provide. In the observed case, attackers additionally used the RAT's access to the victim's banking app to originate a fraudulent loan in parallel with the card fraud.

Group-IB identified 23 WindRelay samples submitted to VirusTotal between November 2025 and July 2026, alongside 7 related SpyNote samples, communicating with four command-and-control IP addresses. Targeting -- inferred from impersonated-institution branding and in-app language -- centers on Czechia, Slovakia, and Slovenia. No specific threat actor or nation-state attribution was published for this campaign.

WindRelay is the latest entrant in an NFC-relay malware lineage that Group-IB and others track as "Ghost Tapping" or "Ghost Tap": ESET first documented the technique in the wild as NGate, targeting Czech bank customers from late November 2023 and escalating to a dedicated Android malware by March 2024 (leading to the arrest of a 22-year-old suspect in Prague carrying over $6,500 in stolen cash); Cleafy documented SuperCard X in April 2025, a Chinese-speaking-operated NFC-relay malware-as-a-service targeting Italian bank and card-issuer customers via smishing/vishing. Group-IB separately tracks the broader Chinese-language fraud-as-a-service ecosystem behind this technique class as "TX-NFC," noting NFC-based attacks on Android rose 188% in the first four months of 2026 versus the same period in 2025 (35,600 attacks blocked). WindRelay's distinguishing feature versus this lineage is its tight coupling with a live-call-controlled RAT (SpyNote) for real-time victim manipulation and parallel loan fraud, rather than NFC relay alone.

MITRE ATT&CK techniques used in TL-2026-2003

Discovery

T1418.001 Security Software Discovery

Command and Control

T1437 Application Layer Protocol; T1663 Remote Access Software

Impact

T1516 Input Injection

Collection

T1533 Data from Local System; T1636.003 Contact List

collection

T1638 Adversary-in-the-Middle

Exfiltration

T1646 Exfiltration Over C2 Channel

defense-evasion

T1655 Masquerading

Initial Access

T1660 Phishing

Affected products and versions in WindRelay Android NFC Relay Malware Paired With SpyNote RAT

  • Google — Android
    Vulnerable versions: NFC/Host Card Emulation-capable Android devices, all supported versions (technique abuses legitimate NFC/Accessibility Service functionality, not a code vulnerability)

Remediation for WindRelay Android NFC Relay Malware Paired With SpyNote RAT

Immediate actions

  • Treat any customer-facing request to install an application or tap a payment card against a phone during an unsolicited, inbound bank-support phone call as a compromise indicator and terminate the session
  • Hold or manually review any loan disbursement that co-occurs with a near-simultaneous physical card/POS or ATM transaction on the same account
  • Block sideloaded (non-Play-Store) application installs that request the NFC + INTERNET + READ_CONTACTS + DUMP permission combination on banking-related devices where such controls are available

Workarounds

  • Educate customers that legitimate banks never ask them to install an application or tap their payment card against their own phone during an unsolicited support call
  • Instruct customers to hang up and independently call their bank's officially published number whenever contacted about a card or account problem

Longer-term hardening

  • Deploy mobile fraud-prevention tooling capable of detecting sideloaded APK installation and Accessibility Service permission grants that occur while an active phone call is in progress
  • Build detection logic on the co-occurrence of NFC, INTERNET, READ_CONTACTS, and DUMP permission grants on newly installed, non-official-store Android applications
  • Apply step-up authentication for loan originations and high-value transactions when an active-call or recent-sideload signal is present on the originating device

Timeline of WindRelay Android NFC Relay Malware Paired With SpyNote RAT

  • ESET Research first observes a threat actor targeting customers of three major Czech banks with the NFC-relay fraud technique that would become NGate, the earliest documented ancestor of the WindRelay/Ghost Tapping malware lineage.
  • The Czech NFC-relay campaign escalates to deployment of the dedicated NGate Android malware, which clones and relays NFC payment card data to ATMs for cash withdrawal; Czech police arrest a 22-year-old suspect in Prague found carrying over $6,500 in stolen cash.
  • Cleafy documents SuperCard X, a Chinese-speaking-operated NFC-relay malware-as-a-service combining smishing/vishing with NFC card data interception, targeting Italian banking and card-issuer customers -- establishing the malware-as-a-service model within the Ghost Tapping family.
  • The earliest WindRelay sample in Group-IB's later-published dataset is submitted to VirusTotal, opening the November 2025-July 2026 collection window Group-IB used to identify 23 related WindRelay samples.
  • The most recent WindRelay sample in Group-IB's 23-sample VirusTotal dataset is submitted, closing the observed November 2025-July 2026 collection window.
  • Group-IB publishes "Gone with the WindRelay," the first public technical disclosure of the WindRelay NFC-relay malware paired with a SpyNote RAT variant, including a case study in which a fraudulent 13-minute bank-impersonation phone call resulted in an unauthorized loan and live NFC-relayed card transactions, targeting victims in Czechia, Slovakia, and Slovenia.
  • Malwarebytes and other outlets, including BleepingComputer and Infosecurity Magazine, publish coverage summarizing the WindRelay/SpyNote campaign, flagging samples as Android/Trojan.NGate.ACRBCF9BBC3C1 and Android/Trojan.NGate.ACR2401245FC5.

Sources cited for WindRelay Android NFC Relay Malware Paired With SpyNote RAT

Detection coverage for TL-2026-2003

As of 2026-08-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2003 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats