# WindRelay Android NFC Relay Malware Paired With SpyNote RAT Enables Real-Time Bank Card "Ghost Tapping" Fraud

> WindRelay is a newly documented Android NFC-relay malware, deployed alongside a SpyNote remote access trojan variant, that captures a victim's live contactless card exchange -- including one-time transaction authentication codes -- and relays it in real time to a criminal-controlled device held against a payment terminal or ATM. Group-IB documented a case in which a vished victim was walked through a 13-minute phone call that resulted in an unauthorized loan and fraudulent NFC-relayed card transactions, part of a set of 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026 that predominantly impersonate financial institutions in Czechia, Slovakia, and Slovenia.

- **Published:** 2026-08-13T00:00:00Z
- **Last reviewed:** 2026-08-13T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2003
- **ID:** TL-2026-2003
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

WindRelay is an NFC relay ('ghost tapping') malware family for Android, first publicly documented by Group-IB on 2026-08-12 in the report "Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme," and independently covered the following day by Malwarebytes. It is deployed as the second stage of a two-malware combo alongside a variant of SpyNote, a long-running, source-code-leaked (2020, v6.4) Android remote access trojan with banking-overlay and full device-control capabilities that has since been commercialized and forked widely (e.g., the CypherRat/SpyNote.C variant sold via Telegram 2021-2022).

The infection chain begins with vishing: a fraudster calls the victim impersonating bank staff, claiming a problem with their card. In Group-IB's documented case study, the entire compromise -- from the opening pretext to fraudulent transaction -- took just 13 minutes, with the live call itself doubling as a real-time control channel the attacker used to talk the victim through each step and defeat hesitation. The victim is guided to sideload a personalized APK (labeled with the victim's own name, indicating prior reconnaissance) that installs SpyNote outside the Play Store. SpyNote abuses Android's Accessibility Service to grant itself the ability to silently install additional packages without further user interaction, and uses this access to sideload WindRelay mid-call. WindRelay requests NFC, INTERNET, READ_CONTACTS, and DUMP permissions -- the last used to detect security tooling on the device, and READ_CONTACTS to harvest further victim leads. The attacker then instructs the victim to tap their payment card against their own (compromised) phone; WindRelay turns the device into a rogue contactless reader, capturing the live chip-to-reader exchange -- including the card's single-use, transaction-specific cryptographic authentication data -- and streaming it over the internet in real time to a second, attacker-held device that presents it to a genuine POS terminal or NFC-enabled ATM. Because the relay happens live, the receiving terminal sees what looks like an ordinary, valid tap, defeating the replay protection that dynamic per-transaction codes are designed to provide. In the observed case, attackers additionally used the RAT's access to the victim's banking app to originate a fraudulent loan in parallel with the card fraud.

Group-IB identified 23 WindRelay samples submitted to VirusTotal between November 2025 and July 2026, alongside 7 related SpyNote samples, communicating with four command-and-control IP addresses. Targeting -- inferred from impersonated-institution branding and in-app language -- centers on Czechia, Slovakia, and Slovenia. No specific threat actor or nation-state attribution was published for this campaign.

WindRelay is the latest entrant in an NFC-relay malware lineage that Group-IB and others track as "Ghost Tapping" or "Ghost Tap": ESET first documented the technique in the wild as NGate, targeting Czech bank customers from late November 2023 and escalating to a dedicated Android malware by March 2024 (leading to the arrest of a 22-year-old suspect in Prague carrying over $6,500 in stolen cash); Cleafy documented SuperCard X in April 2025, a Chinese-speaking-operated NFC-relay malware-as-a-service targeting Italian bank and card-issuer customers via smishing/vishing. Group-IB separately tracks the broader Chinese-language fraud-as-a-service ecosystem behind this technique class as "TX-NFC," noting NFC-based attacks on Android rose 188% in the first four months of 2026 versus the same period in 2025 (35,600 attacks blocked). WindRelay's distinguishing feature versus this lineage is its tight coupling with a live-call-controlled RAT (SpyNote) for real-time victim manipulation and parallel loan fraud, rather than NFC relay alone.

## MITRE ATT&CK

- T1660 Phishing
- T1655 Masquerading
- T1516 Input Injection
- T1663 Remote Access Software
- T1437 Application Layer Protocol
- T1638 Adversary-in-the-Middle
- T1646 Exfiltration Over C2 Channel
- T1636.003 Contact List
- T1533 Data from Local System
- T1418.001 Security Software Discovery

## Sources

- [New Android malware lets criminals use your bank card in real time](https://www.malwarebytes.com/blog/mobile/2026/08/new-android-malware-lets-criminals-use-your-bank-card-in-real-time)
- [Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme](https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/)
- [Android malware combo takes out loans and relays victims' credit cards](https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/)
- [WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam](https://www.infosecurity-magazine.com/news/windrelay-nfc-relay-spynote-rat/)
- [TX-NFC (Ghost Tap): NFC Relay Fraud Threat Profile](https://www.group-ib.com/masked-actors/tx-nfc/)
- [ESET Research discovers NGate: Android malware, which relays NFC traffic to steal victim's cash from ATMs](https://www.welivesecurity.com/en/eset-research/ngate-android-malware-relays-nfc-traffic-to-steal-cash/)
- [SuperCard X: exposing a Chinese-speaker MaaS for NFC Relay fraud operation](https://www.cleafy.com/cleafy-labs/supercardx-exposing-chinese-speaker-maas-for-nfc-relay-fraud-operation)
- [SuperCard X Android Malware Enables Contactless ATM and PoS Fraud via NFC Relay Attacks](https://thehackernews.com/2025/04/supercard-x-android-malware-enables.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2003
