A single 13-minute phone call let a fraudster install two pieces of malicious software and complete both card and loan fraud against a victim, Group-IB reported on August 12.
The live-call sequence: social engineering to sideload in 13 minutes
Group-IB documented a case in which an operator called the victim posing as a bank employee reporting a problem with their card. During that call the attacker walked the victim through installing an app; the remote access trojan (RAT) arrived via the device’s package installer, the standard route for sideloading outside an app store. With the RAT active, the fraudster used remote control to install a second app — the previously unseen NFC relay malware tracked as WindRelay — requiring nothing further from the victim. Group-IB noted no screen sharing was triggered at any point.
SpyNote RAT: personalization and pre-call reconnaissance
Group-IB attributed the RAT used in the incident to a variant of SpyNote. The RAT’s delivered app label carried the victim’s own name rather than a generic or impersonated brand. Group-IB said that label pointed to pre-call reconnaissance harvesting the victim’s name and phone number, and that SpyNote ships with a builder toolkit that lets an operator set a custom app name, label and package name — meaning the personalization is a built-in capability rather than manual effort. Because the app label matched the victim’s name, Group-IB said there was no unfamiliar app name to give the victim pause.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildWindRelay: permissions and contactless relaying
WindRelay’s permissions mapped directly to its purpose, Group-IB reported: NFC to read payment cards, INTERNET to stream captures out live, READ_CONTACTS to reach further targets, and a DUMP permission — unusual in a third-party app — to inspect device state. When the victim tapped their card as instructed, WindRelay behaved as a contactless reader, capturing the live exchange between the card’s chip and the legitimate reader, including the one-time code generated for that transaction. That exchange was streamed in real time to a second device held by the fraudster; that second device then presented itself as the card to a real terminal.
Two attacks in one call: card relay and an opportunistic loan
Using the same remote access established by the RAT, the fraudster also took out a loan through the victim’s banking app. Group-IB characterized the loan as an opportunistic add-on rather than a planned core step of the relay scheme. Card transactions began appearing shortly after the call ended. The combined sequence — social engineering to sideload SpyNote, remote installation of WindRelay, live relay of contactless data, and a further loan disbursement — unfolded within the 13-minute window Group-IB documented.
How banks, security teams, and consumers should react
- Banks: Group-IB recommended flagging loan disbursements that coincide with physical card transactions and alerting on unusual funding patterns tied to concurrent card activity.
- Security teams and app/platform operators: Group-IB advised not to rely on screen-sharing detection as a proxy for remote access, and to generate alerts when app installations from non-official sources occur during an active call.
- Consumers: the incident underscores that a familiar-looking app label can be the result of pre-call reconnaissance and builder-enabled customization; victims may be instructed to sideload an app without obvious warning signs.
Group-IB linked WindRelay to 23 samples uploaded to VirusTotal between November 2025 and July 2026, noting the samples impersonated financial institutions in Czechia, Slovakia and Slovenia. The case illustrates a tightly choreographed pairing of a commodity RAT’s personalization and control features with a novel NFC relay that streams transaction data live to a fraudster-held device.
Group-IB’s technical write-up lays out specific detection and alerting steps; whether affected banks and platforms implement those measures at scale — and whether additional WindRelay variants will appear beyond the 23 VirusTotal samples documented between November 2025 and July 2026 — are concrete questions the record leaves for defenders and investigators to answer.
Original report: https://www.infosecurity-magazine.com/news/windrelay-nfc-relay-spynote-rat/




