Skip to main content

Android Malware WindRelay & SpyNote: NFC Relay for Loan Fraud

4 min read Runtime Rebel Intel
Primary source: bleepingcomputer.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: Victims face real-time credit card fraud and unauthorized loans via a WindRelay and SpyNote Android malware combo.
  • Affected systems: Android devices targeted via social engineering to sideload SpyNote, leading to WindRelay installation and banking app compromise.
  • Remediation: Avoid sideloading unknown apps and verify bank call legitimacy by calling official numbers directly.

Advertisement

Android Malware Combo Facilitates Real-Time NFC Fraud and Loan Theft

A new and sophisticated Android malware combination, involving the WindRelay NFC relay tool and the SpyNote Remote Administration Tool (RAT), is being actively exploited to steal credit card data in real-time and secure unauthorized loans. This dual-threat approach allows attackers to bypass typical security measures through social engineering and direct device compromise, leading to immediate financial losses for victims, according to BleepingComputer.

Understanding the Attack Chain: SpyNote and WindRelay Synergy

The attack typically commences with a social engineering scheme where a fraudster impersonates a bank employee, contacting the victim about an alleged issue with their payment card. During this call, the threat actor directs the victim to sideload a malicious Android application, cleverly disguised as a legitimate banking or utility app. This app is, in fact, the SpyNote RAT. To enhance credibility, attackers personalize the app’s label with the victim’s name. Crucially, victims are instructed to grant Accessibility Service permissions, which then provides the attacker with comprehensive remote access and control over the Android device.

Once SpyNote is established, the attacker remotely installs WindRelay without further victim interaction. The WindRelay component is pivotal for its unique NFC relay capabilities. Victims are then manipulated into tapping their physical payment cards against their compromised phone and entering their PIN. At this stage, WindRelay transforms the Android device into a fraudulent contactless reader, relaying the live Near-Field Communication (NFC) exchange, including critical transaction-specific authentication data, directly to the attacker’s device. This allows the attacker to conduct fraudulent purchases at genuine payment terminals, utilizing the real-time relayed card data and the victim-provided PIN.

Furthermore, the remote control facilitated by SpyNote enables attackers to interact directly with banking applications on the victim’s device to initiate and approve loans in the victim’s name. Group-IB’s investigation revealed that this entire operation, including both the loan origination and credit card data relay, could be executed within a mere 13-minute phone call. This method is distinct from many modern Android malware operations that rely on screen sharing or VNC, as this combo focuses on direct control and relay capabilities primarily through social engineering.

SpyNote RAT Remote Access Capabilities and Broader Impact

SpyNote is a well-known RAT with a history dating back to at least 2021. Its source code was leaked, leading to an increase in detections in late 2022 and early 2023, along with variants like SpyMax and CypherRAT. Beyond its role in the WindRelay attacks, SpyNote possesses extensive data theft capabilities, including:

  • Stealing banking credentials.
  • Exfiltrating Facebook and Google account credentials.
  • Capturing Google Authenticator codes.
  • GPS tracking.
  • Intercepting SMS messages.
  • Activating device microphones and cameras.
  • Generic keystroke logging.

This broad range of capabilities makes SpyNote a significant threat for a variety of data exfiltration and surveillance activities, highlighting the dangers of granting broad permissions to untrusted applications.

Targeted Regions and Mitigating Social Engineering Banking Fraud on Android

Group-IB has identified nearly two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026, communicating with four distinct command-and-control IP addresses. Based on the impersonated organizations and languages used in the social engineering attacks, targeting appears concentrated on Czechia, Slovakia, and Slovenia. The emergence of WindRelay is part of a growing trend of Android NFC malware, following families such as NFCShare, NGate, SuperCard X, and RelayNFC.

Actionable Recommendations for Android NFC Relay Malware Detection and Prevention

Defenders and individual users can take several steps to protect against such sophisticated attacks:

  • Avoid Sideloading Apps: Only download and install applications from trusted sources like the Google Play Store. Avoid installing APK packages from unknown publishers or links provided via unsolicited communications.
  • Scrutinize Permissions: Be extremely cautious when an app requests Accessibility Service permissions or extensive NFC access. Understand why an app needs certain permissions before granting them.
  • Verify Bank Communications: If you receive a call or message from your bank asking you to take urgent action or install software, terminate the call. Instead, independently dial the official customer service number listed on your bank’s website or the back of your card to verify the request.
  • Enable Play Protect: Ensure Google Play Protect is active on your Android device. It continuously scans apps for malicious behavior.
  • Software Updates: Keep your Android operating system and all applications updated to their latest versions to benefit from security patches.

Educating users about the persistent threat of social engineering and the risks associated with sideloaded applications is paramount. Organizations should also consider implementing multi-factor authentication (MFA) for banking transactions and monitoring for unusual activity on customer accounts.

Related: FBI Warns: $388M Lost to Crypto ATM Scams in 2023 – Defense Guide, Flying Eagle Mobile RAT Builder: China’s Infostealer-as-a-Service

Advertisement

Advertisement