WindRelay Malware Attack Drains Accounts in 13 Minutes Using SpyNote RAT and NFC Relay
A sophisticated Android fraud operation combines the SpyNote RAT with WindRelay NFC relay malware to drain victim accounts within minutes, leveraging social engineering and live payment data relay.

A new and alarming Android fraud operation has emerged, capable of draining victim accounts in as little as 13 minutes by combining the SpyNote remote-control tool with a novel NFC relay malware dubbed WindRelay. This potent malware pairing grants criminals remote access to a victim's banking application and the ability to relay live NFC payment data, effectively bypassing standard security measures and enabling card-present fraud.
The attack chain begins with a social engineering tactic where a threat actor, posing as a bank employee, contacts the victim with a fabricated issue concerning their payment card. The victim is then coerced into installing a seemingly legitimate application, often disguised with their own name, onto their device. While the victim remains on the call, the attackers leverage SpyNote's capabilities, which exploit Android's Accessibility Services, to gain comprehensive remote control over the device. This allows them to perform actions such as initiating a loan in the victim's name without the victim's direct input or even screen sharing.
Following the initial compromise with SpyNote, the attackers proceed to install the WindRelay malware. The victim is then instructed to tap their physical payment card against their phone, ostensibly as part of a security verification process. However, this action allows WindRelay to capture the live NFC data exchange between the card and the payment terminal. This live data is then relayed in real-time over the internet to a second device controlled by the attacker.
This relayed NFC data is subsequently presented to a legitimate payment terminal by the second attacker-controlled device. Because the transaction data is live and mimics a genuine chip conversation, it can bypass many standard security checks that might flag a simple stolen card number. This technique allows for card-present fraud that appears legitimate to merchants and payment processors, making it significantly harder to detect than traditional online card theft.
Group-IB, whose research uncovered this campaign, highlighted that the dual payout paths—digital lending via remote banking access and card-present fraud via NFC relaying—make this attack particularly lucrative. The speed at which these actions occur leaves little time for either the bank or the customer to identify suspicious activity, challenge a transaction, or prevent account takeover. The malware has been observed targeting users in Czechia, Slovakia, and Slovenia.
To combat this threat, users are strongly advised never to install applications or tap their payment cards based on unsolicited calls. Legitimate financial institutions should always be contacted independently through verified channels. Organizations should monitor for apps installed from unofficial sources, especially those requesting extensive permissions like accessibility or device administration, and be wary of unusual loan requests or rapid, timed transactions.
Defenders are encouraged to look beyond traditional signature-based detection and focus on identifying unusual permission combinations and implementing out-of-band confirmations or delays for high-risk operations like loan applications. Monitoring for unusual NFC relay activity and cross-referencing it with lending and transfer data can help uncover the full extent of the damage. This campaign underscores a broader trend in contactless payment fraud, where sophisticated social engineering is paired with advanced malware to exploit user trust and bypass security protocols.