A new Android malware strain called WindRelay is being used alongside the SpyNote remote administration tool to steal payment card data and relay it to attackers in real time. The technique can allow criminals to use genuine payment terminals to carry out fraudulent transactions.
In a case investigated by cybersecurity company Group-IB, a fraudster allegedly posed as a bank employee and told a victim there was an issue with their payment card. The victim was persuaded to install SpyNote, disguised as a legitimate application, and grant it Accessibility Service permissions. This gave the attacker remote control over the Android device.
The attacker also customised the malicious application’s label using the victim’s name to make it appear more legitimate.
After gaining remote access through SpyNote, the attacker installed WindRelay without requiring further action from the victim. The attacker then accessed the victim’s banking application and took out a loan in the victim’s name.
The victim was subsequently instructed to tap a payment card against the compromised phone and enter the card PIN. WindRelay then turned the Android device into a fraudulent contactless reader.
The malware captured the live NFC communication between the card and the phone, including transaction-specific authentication data, and transmitted it to an attacker-controlled device. The stolen information was then used to make purchases at a genuine payment terminal.
According to Group-IB, the entire operation took place during a 13-minute phone call, with the fraudulent transactions approved using the PIN provided by the victim.
The combination of SpyNote and WindRelay gives attackers both remote access to an Android device and a method to capture and relay payment card data. Such NFC relay attacks typically depend on social engineering, with victims being persuaded to install malicious applications, provide sensitive permissions and physically tap their cards against compromised phones.
SpyNote and related malware variants, including SpyMax and CypherRAT, have been circulating since at least 2021.
Group-IB identified almost 2 dozen WindRelay samples uploaded to VirusTotal between November 2025 and July 2026. The samples communicated with 4 command-and-control IP addresses. The campaign appears to have focused mainly on Czechia, Slovakia and Slovenia, based on the organisations impersonated and the languages used.
Android users are advised to avoid installing APK files from outside Google Play unless the publisher is trusted. Users should also be cautious when applications request NFC access or other sensitive permissions.
People receiving urgent calls claiming to be from their bank should end the call and contact the bank independently using the official number listed on its website.
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter
About us:
The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.


