
WindRelay Android Malware Turns a Card Tap Into Bank Fraud
Researchers documented a live-call scam combining phone takeover malware with an NFC relay tool, allowing criminals to abuse both mobile banking and a victim's physical payment card.
The short version
What you need to know
- Group-IB documented a fraud chain in which a caller persuaded a victim to install a personalised Android app and grant powerful Accessibility access.
- SpyNote remote-access malware was then paired with WindRelay to pass a live payment-card NFC exchange to an attacker-controlled device; observed targeting was in Czechia, Slovakia and Slovenia.
- A VPN cannot stop social engineering, malicious sideloaded apps, Accessibility abuse or a live NFC relay. Refuse unsolicited app-installation, card-tap and PIN instructions, then contact the bank through an independently verified channel.
What did researchers find?
Group-IB reported on 12 August that it had investigated a fraud chain combining a SpyNote Android remote-access trojan with newly tracked NFC relay malware called WindRelay. In the documented case, the interaction unfolded during a live call in roughly 13 minutes.
The research identified 23 WindRelay samples uploaded between November 2025 and July 2026 and observed campaigns aimed at Czechia, Slovakia and Slovenia. That does not establish worldwide prevalence, but the social-engineering pattern is relevant anywhere mobile banking and contactless cards are used.
How the scam chain worked
A caller impersonating a bank persuaded the victim to install a personalised app outside the official store and grant Android Accessibility permissions. Those permissions gave the SpyNote malware powerful remote-control capabilities. Group-IB says the attacker then used SpyNote to deploy WindRelay and interact with the victim's banking app.
The attackers allegedly initiated a loan through the banking app, then instructed the victim to tap a physical payment card against the phone and enter its PIN. WindRelay passed the live NFC exchange over the internet to attacker-controlled equipment, creating a second route for purchases or withdrawals. The victim's cooperation was engineered through deception; an ordinary card tap did not infect the card.
What Android and banking users should do
A bank should not ask you during an unsolicited call to sideload an app, grant Accessibility control, tap a payment card against your phone or disclose its PIN. End the call and contact the bank using the number printed on the card or the official app, not a number supplied by the caller.
Keep app installation from unknown sources disabled, review which apps have Accessibility access, and remove anything you do not recognise. If you followed similar instructions, disconnect the phone from networks, call the bank from another trusted device, freeze affected cards or accounts, and seek the bank's fraud and device-cleanup guidance. Changing a password on a phone that remains remotely controlled may simply expose the new password.
Where a VPN helps — and where it does not
A VPN can encrypt traffic on an untrusted local network. It cannot determine whether a caller is really from a bank, stop a user granting dangerous permissions, remove a remote-access trojan or prevent an NFC exchange that the compromised phone is deliberately relaying.
The malware's traffic may itself travel through an encrypted channel, so seeing a VPN icon is not evidence that the device is clean. App provenance, permission control, supported software, bank-side fraud controls and quick incident reporting matter far more in this scenario than changing the device's public IP address.
VPN Rocks view
This attack is persuasive because each individual action can be framed as a security check: install an app, allow access, tap a card, enter a PIN. Taken together, those requests are a clear stop signal. A legitimate bank can be called back through an independently verified route.
Consumers should also avoid treating malware as only a technical download problem. The strongest control in this chain is refusing the live caller's instructions before powerful permissions and card access are handed over.
Primary reading
Sources and further reading
We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.


