New Android Malware Chain Turns Bank Support Scams Into NFC Card Fraud

Researchers uncovered an Android malware chain combining SpyNote and WindRelay to enable remote phone control, banking fraud, and live NFC card abuse.

Aug 14, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

It took a threat actor just 13 minutes to turn a routine bank support call into a remote, live contactless card fraud operation.

Group-IB found malware used in a campaign targeting victims via fake bank support calls, in which attackers persuaded them to install malicious software on their Android devices. Once the phone was compromised, the attackers had a platform to commit financial fraud.

The campaign reflects a broader shift in mobile fraud toward attacks that chain device compromise with payment technology. NFC-enabled malware has already emerged as a growing threat, but WindRelay shows how that technique can be chained with another malware to create a more complete fraud operation.

One compromised phone, two ways to steal money

The attack begins with social engineering. In the case investigated by Group-IB, criminals used a phone call to convince the victim to install a seemingly legitimate app.

Group-IB found that the app was a customized version of SpyNote, an Android remote access trojan (RAT). To make the attempt more credible, the attackers personalized the malware with information about the target, including the victim’s name.

The SpyNote app was sideloaded, meaning it was installed from outside the official Google Play Store. The victim was also persuaded to grant the Android Accessibility Service permission, thereby enabling the attacker to access screen content remotely.

That access was the turning point. Once SpyNote was running, the attacker could remotely control the phone and install WindRelay.

The two malware therefore served different roles in the same attack: SpyNote controlled the phone, while WindRelay handled the card fraud.

Group-IB found that the attackers took out a loan in the victim’s name and used WindRelay to transmit live NFC transactions after instructing the victim to make a payment

The result was a single attack that combined conventional banking fraud with contactless card fraud, rather than relying on just one route to steal money.

Advertisement

Why an attack this complex could still work

An interesting aspect of this campaign is how complex it appears yet how effective it is. The attacker must first conduct reconnaissance on the target before launching a call. They need to persuade a target not just to install an app but to sideload it, and convince them to use their card. 

Each step involves a different kind of trick to work. 

windRelay NFC
Image: Group-IB

That helps explain why the campaign should not be dismissed simply because it requires several things to go right. Once the attacker has convinced them to trust the call and grant SpyNote the necessary access, much of the remaining operation happens remotely.

Google recommends getting apps from Google Play and warns that software from other sources can put devices and personal information at risk.

WindRelay is notable not because it introduces an entirely new form of fraud, but because it connects several existing techniques into one fast-moving attack. A fake support call can lead to remote device control, banking fraud, and live NFC abuse within minutes.

For users, the clearest warning sign comes much earlier: a bank representative should not need you to sideload an app, grant Accessibility access, or use your payment card to resolve a support issue.

Other News: Researchers have warned that attackers may be able to abuse synced passkeys stored in Google Password Manager, potentially turning a compromised Google account into a broader authentication risk.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.