Bank Imposter Calls Trick Victims Into NFC Card Relay

Help Net Security · High sophistication
Last updated August 17, 2026

Researchers reported a real-world phone scam where criminals impersonated a victim’s bank and coached the victim into installing an Android app. The installed remote-access malware let the fraudster silently add a second NFC relay app that streamed the victim’s payment card data to a fake terminal, enabling fraudulent transactions and even a loan taken out in the victim’s name.

How the attack worked

This case began with a live phone call in which the fraudster claimed to be from the victim's bank and said there was a problem with the payment card. Rather than sending a link by text or email, the caller stayed on the line and walked the victim step by step through installing an app to "fix" the issue. That app was SpyNote, a remote access trojan, but its label had been customized to show the victim's own name rather than a generic or unfamiliar title.

Once SpyNote was installed and remote access was established, the fraudster quietly installed a second app, WindRelay, without needing any further action from the victim. WindRelay relayed the victim's live payment card data over NFC to the attackers, who used it against a fake merchant terminal to push through fraudulent transactions. In one documented case, within a 13 minute call the fraudster installed the RAT, initiated a loan through the victim's own mobile banking app, and streamed card data, with transactions appearing on the account shortly after the call ended.

Why it succeeded

The attack relied on the victim staying engaged on a live call for the entire incident, which kept them focused on following instructions rather than questioning them. Personalization was a key trust signal: an app labeled with the victim's own name looks far less suspicious than one with a generic or odd name. Because the fraudster guided the install directly, the victim never had reason to second guess the source of the app until it was too late. Every transaction was also approved using the PIN the victim entered themselves, meaning the fraud looked legitimate from the bank's perspective at the moment it happened.

What to watch for

  • Unsolicited calls claiming an urgent card problem that push for immediate action
  • Being guided, during a call, to install any app on your phone
  • Pressure to remain on the line while completing banking actions or entering a PIN
  • An app name or label that looks personalized or unusually familiar, which can be a fabricated trust signal

Building resistance

Treat unsolicited calls claiming to be from a bank as suspicious by default. Hang up and call back using the number on the back of the card or the bank's official app or website rather than any number or link provided during the call. Never install an app because someone on the phone instructs you to, especially while they keep you engaged. Recognize that trust signals like a personalized app name can be faked, since builder toolkits let operators customize an app's label for each target. If a PIN was entered or a transaction completed during a suspicious call, assume compromise and report it immediately, since related fraud can appear on the account within minutes of the call ending.

Key findings

  • Attack begins with a live phone call where the fraudster pretends to be the victim’s bank and claims there is a problem with the card.
  • Victim is guided to install SpyNote (a remote access trojan); the app label is customized to show the victim’s own name to reduce suspicion.
  • After remote access is gained, the fraudster installs a second app (WindRelay) without further victim action.
  • WindRelay relays live payment card data over NFC to attackers in real time, enabling transactions via a “fake merchant terminal.”
  • In a documented case, within a 13-minute call the fraudster installed the RAT, took out a loan via the victim’s mobile banking app, and streamed card data; transactions appeared shortly after the call ended.
  • Group-IB observed 23 samples (Nov 2025–Jul 2026) and campaigns targeting victims in Czechia, Slovakia, and Slovenia; four C2 IPs were linked to NFC relay activity.
  • Samples were tailored per victim and country, including victim-specific names and local-language interface text.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Customer support/call center staff, Mobile device users.
  • Affected industries: Banking/Financial Services, Consumers/Individuals.
  • Attack channels: vishing.
  • Impersonated: Victim’s bank, Victim’s bank / bank support.

Red flags to watch for

  • Unsolicited call claiming urgent card issue and pushing immediate action
  • Caller guides the victim to install an app during the call
  • Pressure to stay on the line while completing sensitive actions (banking, PIN entry)
  • App identity is unusual (an app named after the user is not normal for banks)
  • Customization of app name/label to build trust
  • Installing apps from a link or guidance during a cold call
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fraudster get access to the victim's phone?

The fraudster called pretending to be from the victim's bank, claimed there was a card problem, and guided the victim to install an app themselves, which turned out to be the SpyNote remote access trojan.

What did the second app do?

After remote access was gained, the fraudster installed a second app called WindRelay without further victim action; it relayed live payment card data over NFC to attackers in real time, enabling transactions via a fake merchant terminal.

Why did the fake app fool the victim?

The app's label was customized to show the victim's own name instead of a strange or generic one, which lowered the victim's guard since SpyNote's builder toolkit allows per-target customization.

What should someone do if they suspect this happened to them?

If a PIN was entered or transactions occurred during a suspicious call, assume compromise and report it immediately, since fraud can appear on the account shortly after the call ends.

Read the video transcript

You get a call: “This is your bank, there’s a problem with your card, stay on the line.” Sounds routine, right? In one real case, during a 13‑minute call, the caller walked the victim through installing an Android app called SpyNote, renamed to show the victim’s own name, then silently pushed a second app, WindRelay, to stream their card data over NFC. The victim stayed on the call, entered their PIN in their real banking app, and minutes after hanging up, saw card charges and even a loan taken out in their name, approved with the PIN they typed themselves. If any “bank” caller ever tells you to install an app, hang up, then call the number on your card or in your banking app and ask if the call was real.

Similar attacks

Fake Bank Calls Trick Victims Into NFC Card Fraud

Fake Bank Calls Trick Victims Into NFC Card Fraud

Researchers described a real scam where criminals called victims pretending to be bank support and convinced them to install a “legitimate” Android app. The app was actually SpyNote malware, giving the attacker remote control of the phone, after which a second tool (WindRelay) was used to relay…

August 14, 2026
Fake Bank Call Triggers “Ghost Tapping” Card Fraud

Fake Bank Call Triggers “Ghost Tapping” Card Fraud

Researchers described a real scam where criminals impersonated a bank on a phone call to trick a victim into installing a malicious Android app. The attackers then remotely controlled the phone and guided the victim to tap their payment card and enter their PIN, allowing real-time contactless fraud…

August 13, 2026
Fake IT Help Desk Calls Hit Private Equity

Fake IT Help Desk Calls Hit Private Equity

Researchers say a threat group tracked as UNC6671 is calling employees and posing as IT help desk staff to steal login credentials and multi-factor authentication (MFA) tokens. After gaining access, the attackers reportedly exfiltrate large amounts of corporate data and then issue extortion…

August 11, 2026
Fake Teams “IT Support” Calls Hijack PCs via Quick Assist

Fake Teams “IT Support” Calls Hijack PCs via Quick Assist

Attackers are calling employees on Microsoft Teams while pretending to be internal IT support, then persuading them to approve a Microsoft Quick Assist remote-control session. Once the employee approves, the attacker can take control of the computer and use PowerShell to install a Go-based backdoor…

July 28, 2026
Bank Impersonation Phish Pushes Remote Tool

Bank Impersonation Phish Pushes Remote Tool

A real, active phishing campaign impersonating Bank of America tricks victims into downloading a fake “Account Guard” that installs ScreenConnect remote access on Windows, while Mac users are redirected to a credential-stealing page asking for banking and identity details. Separately, Microsoft…

August 6, 2026
Fake Bank of America Email Pushes Hidden ScreenConnect

Fake Bank of America Email Pushes Hidden ScreenConnect

Attackers are impersonating Bank of America in mass phishing emails to pressure people into clicking a link “to avoid account restrictions.” Mac users are led to a fake login page that steals credentials and personal/financial data, while Windows users are tricked into installing a ScreenConnect…

August 5, 2026