cybersecurity

WindRelay and SpyNote Combine in a New NFC Payment Fraud Scheme

Group-IB has uncovered WindRelay, an NFC relay malware used with SpyNote RAT in a social-engineering campaign that combines Android remote access with fraudulent card transactions.

Xcademia Team

Xcademia Research Team

Aug 13, 20267 min read2 views
Share:
WindRelay and SpyNote Combine in a New NFC Payment Fraud Scheme

Introduction

Cybersecurity researchers at Group-IB have identified a previously unseen Android malware family called WindRelay, which is designed to intercept NFC payment data and relay it to an attacker-controlled device.

The malware was observed alongside SpyNote, a Remote Access Trojan that provides attackers with remote control over an infected Android device. According to Group-IB, the combination was used as part of a social-engineering fraud operation in which attackers stayed on a live phone call with victims while directing them through the infection process.

The research highlights a growing overlap between mobile malware, social engineering and payment fraud.

A multi-stage attack targeting Android users

The investigated campaign began with an attacker impersonating a bank employee. The victim was persuaded to install an Android application that appeared to be associated with the victim personally.

Group-IB reported that the application contained SpyNote functionality. Once installed, the malware provided the attacker with remote access to the victim's device.

The attacker then used that access to deploy WindRelay.

This created a layered attack chain:

Bank impersonation → Malicious Android application → SpyNote RAT → WindRelay → NFC data relay → Fraudulent transaction

The combination is significant because the attacker did not rely solely on stolen usernames, passwords or banking credentials. Instead, the operation attempted to manipulate the victim's physical payment card through the compromised smartphone.

How WindRelay works

WindRelay is designed to interact with NFC communications.

When a victim taps a compatible payment card against the infected Android phone, the malware can capture information exchanged through the NFC interface. That information can then be transmitted to an attacker-controlled device.

The relay mechanism is intended to bridge the communication between the victim's physical card and a remote device controlled by the fraudster.

This gives the attacker a way to participate in a payment process without having physical possession of the victim's card.

info-1

SpyNote plays a different role from WindRelay.

While WindRelay focuses on NFC-related activity, SpyNote provides remote access to the Android device. This remote-control capability allowed the attacker to interact with the compromised phone during the fraud operation.

Group-IB observed the attacker remaining connected to the victim through a live call. This allowed the attacker to guide the victim through actions on the device while simultaneously controlling the compromised environment.

The approach demonstrates how remote-access malware can become more dangerous when combined with direct social engineering.

Instead of relying entirely on automated malware behaviour, the attacker could actively manipulate the victim and the infected device during the same session.

The role of the live phone call

According to Group-IB, the investigated incident involved a phone conversation lasting approximately 13 minutes.

During the call, the attacker reportedly impersonated a bank representative and instructed the victim through several steps.

The victim installed the malicious application, after which the attacker obtained remote access and deployed WindRelay. The victim was subsequently instructed to tap their bank card against the smartphone and provide their PIN.

Group-IB also reported that the attacker used the remote access session to take out a loan in the victim's name.

The incident illustrates why social engineering remains an important component of modern mobile fraud. Technical malware capabilities can be combined with real-time human interaction to persuade victims to perform actions that security software alone may not prevent.

Why the malicious application appeared convincing

One notable detail from the investigation was the application's personalisation.

Group-IB reported that the RAT application was labelled using the victim's own name. This can make a suspicious application appear more legitimate to someone who has already been persuaded that they are communicating with their bank.

The technique is simple, but it demonstrates how attackers can combine technical access with psychological manipulation.

The malware does not necessarily need to convince the victim through sophisticated software design if the attacker has already established trust through a phone call.

WindRelay's Android permissions

Group-IB identified several permissions associated with the malware, including permissions related to NFC access, internet connectivity, network state and contacts.

Among the permissions highlighted in the research were:

  • NFC access

  • Internet access

  • Network-state information

  • Contact access

  • Additional permissions associated with the malware

These permissions provide insight into the functionality and intended operating environment of the malware.

Group-IB also identified custom-defined permissions within the application.

The company did not provide specific information about every permission's operational use.

info-2

From compromised phone to payment relay

The most important technical element of the campaign is the NFC relay concept.

Near Field Communication is commonly used for short-range wireless interactions, including contactless payments. In this case, the compromised smartphone becomes part of an interception and relay process.

The victim's card communicates with the infected phone.

WindRelay captures the relevant NFC communication and transmits it to infrastructure controlled by the attacker.

The attacker can then use another device as part of the relay process.

This means the fraud operation combines a physical payment card with a digitally compromised Android device and an attacker-controlled endpoint.

info-3

A convergence of mobile malware and payment fraud

The WindRelay case is notable because it connects several attack techniques that are often considered separately.

The first is social engineering, where an attacker manipulates a victim into installing software and following instructions.

The second is remote-access malware, represented by SpyNote, which gives the attacker control over the compromised Android environment.

The third is NFC interception, where WindRelay interacts with contactless payment communication.

Together, these elements create a fraud workflow that crosses the boundary between digital account compromise and physical payment activity.

The announcement highlights a broader industry shift toward attacks that combine multiple techniques rather than depending on a single malicious capability.

Why Android users should pay attention

The incident reinforces the importance of treating unsolicited banking instructions with caution.

A legitimate bank representative should not require customers to install an unfamiliar application simply to resolve an account issue. Users should also be cautious when asked to grant extensive permissions or follow unusual payment-related instructions during a phone call.

Remote-control applications can be particularly dangerous when installed at the request of an unknown caller because they may allow another person to interact with the device.

Users should therefore avoid installing applications supplied through unexpected calls, messages or links, particularly when the installation is accompanied by instructions to reveal payment information or perform unfamiliar transactions.

What organisations can learn from the campaign

Financial institutions and security teams face a more complex fraud environment when malware, social engineering and payment technologies are combined.

Traditional fraud controls focused on stolen credentials may not address every stage of an operation like this.

For enterprises, this could mean greater attention to mobile-device security, application installation behaviour, remote-access activity and unusual payment patterns.

Banks can also benefit from educating customers about impersonation scams and unexpected requests to install applications.

However, specific defensive measures beyond those described in the research were not disclosed in the announcement.

The broader security picture

WindRelay demonstrates how attackers can use a compromised smartphone as an intermediary between a physical payment card and remote infrastructure.

The significance of the discovery is therefore not limited to a new Android malware family.

It shows how modern fraud operations can combine:

Human manipulation + mobile malware + remote access + NFC technology + payment fraud

Each component contributes a different capability.

Social engineering establishes trust. SpyNote provides remote control. WindRelay interacts with NFC communication. The attacker then attempts to use the resulting access for financial fraud.

This layered approach makes the attack harder to understand as a conventional malware infection because the victim is actively involved throughout the process.

What users should remember

The WindRelay case provides several practical security lessons:

  • Do not install applications at the request of unsolicited callers claiming to represent a bank.

  • Do not provide payment-card details or PINs during unexpected support calls.

  • Be cautious about granting remote-access permissions to unfamiliar applications.

  • Verify banking requests through the institution's official communication channels.

  • Treat unexpected NFC or contactless-payment instructions as suspicious.

  • Keep Android devices updated and remove applications that are no longer trusted.

The company did not provide specific information about additional victim-protection measures beyond the details described in its research.

Conclusion

Group-IB's discovery of WindRelay shows how NFC technology can become part of a sophisticated fraud workflow when combined with Android remote-access malware and social engineering.

The use of SpyNote alongside WindRelay allowed attackers to combine remote control of a victim's smartphone with manipulation of a physical payment card.

For security professionals, the case highlights the importance of viewing mobile malware, social engineering and payment fraud as interconnected risks rather than isolated threats.

For everyday users, the central lesson is straightforward: an unexpected caller asking you to install an application, grant remote access or use your payment card in an unusual way should be treated with caution.

Source: Group-IB

#WindRelay#AndroidMalware#SpyNote#NFCFraud#MobileSecurity#CyberFraud#SocialEngineering#PaymentSecurity

About the Author

X
Xcademia Team
Xcademia Research Team
Share:
Learn to stop attacks like this oneCybersecurity Engineer Bootcamp: live cohorts enrolling now, Career+ support included.