Threat actors have found a way to transform ordinary Android smartphones into remote-controlled card readers. In a matter of minutes, they can siphon data from contactless payment cards and authorize fraudulent transactions thousands of miles away. The scheme, uncovered this week, pairs an established remote-access tool with a purpose-built NFC relay program. Banks and security teams now face a fast-moving fraud vector that collapses the window between compromise and cash-out.
Group-IB first documented the operation in a detailed analysis published yesterday. Researchers there tracked the campaign across Central and Eastern Europe. They observed attackers complete reconnaissance, install malware, extract a loan, and relay card data all inside a single 13-minute phone call. The operation’s efficiency stunned investigators. One victim lost funds from both an approved loan and subsequent contactless purchases.
The malware at the center is called WindRelay. It functions as a live bridge. When a victim taps a physical card against the infected device, WindRelay captures the NFC signals and streams them instantly to an attacker-controlled terminal. No static data is stored. The relay happens in real time. This preserves the dynamic authentication codes that many anti-fraud systems rely on. The result looks like a legitimate card-present transaction.
But WindRelay does not work alone. It depends on SpyNote, a remote-access trojan leaked on underground forums in 2016. The Register reported that attackers use vishing calls to trick victims into installing the personalized SpyNote variant. The app icon and label carry the victim’s own name. “Such tactics are more effective at weakening a victim’s natural defenses and suspicions,” Group-IB researchers wrote in their report. The personalization removes a common red flag at the precise moment hesitation peaks.
And the call continues. The fraudster stays on the line, guiding the victim through “verification” steps. SpyNote’s accessibility service grants full remote control. No screen sharing is required. The attacker silently downloads and activates WindRelay without further victim interaction. BleepingComputer noted that this silent installation turns the phone into a fraudulent point-of-sale device while the conversation remains active.
The sequence moves quickly. First the loan application is approved through the banking app under remote control. Then the victim is told to tap their card and enter a PIN for additional “security checks.” WindRelay intercepts the full EMV exchange. The data travels over WebSocket connections to the attacker’s emulator device. There it is replayed as if the physical card were present. The Hacker News described the two-component setup: a reader on the victim’s phone and an emulator on the fraudster’s end. They synchronize commands and responses through a command-and-control server.
Group-IB identified 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026. The files mimic banking institutions in Czechia, Slovakia, and Slovenia. Some include localized text and personalized user-interface elements. The threat actor appears capable of dynamically generating these apps per target. Pavel Naumov, senior security researcher at Group-IB, captured the significance. “This case shows that modern fraud rarely relies on one technique. Here, the fraudster combined three capabilities in a single session — a live social engineering call, a personalized RAT for remote device control, and an NFC relay malware for physical cash-out.”
The operation expands on earlier NFC relay campaigns. Zimperium documented a surge in similar Android malware abusing host card emulation starting in 2024. Malwarebytes reported on SuperCard X in April 2025, which also turned phones into malicious tap devices after victims were tricked via smishing. Yet the WindRelay-SpyNote combination introduces tighter integration and live-call persistence. The 13-minute timeframe leaves banks little chance to intervene with fraud alerts or account freezes.
TechRadar highlighted the highly targeted nature of these attacks. Only a limited number of victims appear affected so far, consistent with the reconnaissance and personalization involved. The Register added that the scheme has been observed in Czechia, Slovakia, and Slovenia, with possible spread to Poland and Brazil based on command-and-control infrastructure. Attackers monetize through both digital loans and physical card-present purchases. This dual payout maximizes returns from a single compromise.
Technical permissions reveal the intent. WindRelay requests NFC access for reading cards, full internet connectivity for streaming data, and device inspection capabilities. SpyNote brings broader remote-control functions, including the ability to navigate banking apps and approve transactions. The combination bypasses many traditional mobile security layers. Victims never see suspicious overlays or unusual prompts once the initial app is installed.
Security firms have begun updating detection signatures. Yet the custom-built nature of WindRelay and the personalized delivery complicate scalable defenses. Group-IB researchers recommend treating any unexpected call from a bank with extreme caution, especially those requesting app installations. They also advise adding extra approval steps for loan applications and monitoring for sideloaded packages on corporate or high-value accounts.
The discovery arrives at a moment when contactless payments dominate daily transactions across Europe. Consumers have grown accustomed to tapping cards or phones without a second thought. That habit now carries hidden risk when the phone itself has been turned against its owner. Fraud teams must adapt detection models to account for live NFC proxying rather than static data theft.
Earlier this year, Kaspersky examined similar NFC gate relay attacks and warned of their scalability. The WindRelay campaign validates those concerns while demonstrating how social engineering can lower the technical bar for attackers. No longer does the criminal need physical proximity to the card. The victim’s own device does the heavy lifting, and the phone call keeps the victim cooperative throughout.
Industry observers expect the tactic to proliferate. SpyNote’s long availability on criminal markets means many operators already possess the tool. Building or acquiring an NFC relay component has become straightforward for technically capable groups. The barrier is no longer the code. It is the convincing phone conversation and the ability to obtain accurate victim details in advance.
Banks may need to revisit callback verification procedures and implement stricter controls on remote app installation prompts. Device manufacturers could consider enhanced warnings around accessibility service grants or NFC activity during unexpected calls. For individual users, the lesson is simple. Never install banking-related apps at the direction of an unsolicited caller. Verify the request through official channels before acting.
The speed of this attack should worry risk managers. Thirteen minutes is faster than many transaction monitoring systems can react, especially across borders. As one Group-IB analyst put it, the fraudster remains on the line for the entire session, turning the victim’s phone into both a compromised endpoint and an unwitting accomplice. The combination of persistence, personalization, and real-time relay makes this a particularly sticky problem for the payments industry.
Further analysis of the command-and-control infrastructure may reveal additional victims or related campaigns. For now, the public disclosure serves as an early warning. Android users in targeted regions, and potentially beyond, face a credible new threat that exploits both human trust and hardware capabilities in one tightly choreographed sequence.