Fake Bank Calls Trick Victims Into NFC Card Fraud

eSecurity Planet · High sophistication
Last updated August 17, 2026

Researchers described a real scam where criminals called victims pretending to be bank support and convinced them to install a “legitimate” Android app. The app was actually SpyNote malware, giving the attacker remote control of the phone, after which a second tool (WindRelay) was used to relay live NFC (tap-to-pay) transactions and steal money within minutes.

How the Attack Worked

This attack, documented by Group-IB, began with a phone call. The caller impersonated bank support staff and convinced the victim that an account issue needed to be resolved by installing an app. That app was a customized version of the SpyNote Android remote access trojan, personalized with the victim's own name to appear credible. Because it was sideloaded from outside Google Play, the victim also had to be talked into granting the Android Accessibility Service permission, which gave the attacker the ability to view and control the device's screen remotely.

Once the attacker had remote control, they deployed a second tool, WindRelay, to relay live NFC (tap-to-pay) transactions. According to Group-IB, the entire sequence, from the initial support call to a completed live NFC fraud transaction, took about 13 minutes. Attackers reportedly also took out a loan in the victim's name as part of the broader fraud.

Why It Succeeded

The scheme worked because it layered several trust-building steps on top of each other:

  • A phone call created urgency and an appearance of legitimate bank contact.
  • Personalizing the malicious app with the victim's name reduced suspicion.
  • Framing the install and permission request as necessary steps to "fix" an account issue made the requests feel routine rather than alarming.
  • Once remote access and Accessibility permissions were granted, the victim had little visibility into what was actually happening on their device.

What to Watch For

Key red flags identified in this attack pattern include:

  • A caller claiming to be bank support who asks you to install an app from outside the official app store.
  • Requests to enable Android Accessibility Service permissions for an app you did not seek out yourself.
  • Pressure to act quickly during an unsolicited support call.
  • Being instructed to use your payment card as part of a "support" process.
  • Unexpected financial activity, such as a loan appearing in your name that you did not initiate.

Building Resistance

Awareness efforts should reinforce a few concrete habits. Treat unsolicited bank support calls with suspicion, and instead hang up and call back using the number on the back of your card or the bank's official website. Only install apps from official stores such as Google Play, never based on instructions from a phone call. Be cautious about granting Accessibility permissions, since this level of access can enable full remote control of a device. Finally, remember that a legitimate bank representative should never need you to sideload an app, grant special device permissions, or use your payment card to resolve a support issue. These habits directly counter each step used in this real-world attack chain.

Key findings

  • Attackers used fake bank support phone calls to persuade victims to install a malicious Android app.
  • The initial app was a customized SpyNote Android RAT, personalized with victim details (e.g., the victim’s name) to appear credible.
  • Victims were convinced to sideload the app (outside Google Play) and grant Accessibility permissions, enabling remote control.
  • After compromise, attackers remotely installed WindRelay and used it to relay live NFC transactions, enabling contactless card fraud.
  • Group-IB reported the end-to-end conversion from support call to live NFC fraud took about 13 minutes.
  • Attackers also conducted conventional banking fraud steps such as taking out a loan in the victim’s name.

Who’s being targeted

  • Commonly targeted roles: All staff (mobile device users), Finance / cardholders (corporate card users), Executives (high-value targets for fraud), Customer support teams (to recognize and warn about callback scams).
  • Affected industries: Banking/Financial services, Consumers/retail banking customers.
  • Attack channels: vishing.
  • Impersonated: Bank support / bank representative.

Red flags to watch for

  • Caller asks you to install an app outside the official app store
  • Caller asks for Android Accessibility Service permissions
  • Pressure to act immediately during a “support” call
  • Being told to use your payment card as part of “support”
  • Unexplained urgency and scripted instructions while on the phone
  • Unexpected financial activity such as a loan opened in your name
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers trick victims into installing malware?

Attackers called victims pretending to be bank support and convinced them to sideload a customized Android app that was actually the SpyNote remote access trojan.

What made the malicious app seem trustworthy?

The SpyNote app was personalized with the victim's own name, which made it appear legitimate during the phone call.

How fast did the fraud happen once the app was installed?

Group-IB reported that the end-to-end process from the initial support call to live NFC fraud took about 13 minutes.

What permission did the attackers need to control the phone remotely?

They persuaded victims to grant the Android Accessibility Service permission, which let the attacker view and control screen content remotely.

Read the video transcript

Imagine this: a “bank support” call, and 13 minutes later, your Android is running live tap-to-pay fraud. Researchers saw this: caller pretends to fix an issue, walks the victim through installing a “support” app that’s actually SpyNote, sideloaded outside Google Play, then tricks them into granting Android Accessibility so they can drive the phone remotely. Once SpyNote is in, they push WindRelay, tell the victim to 'make a test payment,' and relay live NFC transactions in the background, plus classic fraud like taking out a loan in the victim’s name. Here’s your move: if “bank support” ever asks you to install an app or use your card on that call, hang up and call the number on the back of your card instead.

Similar attacks

WindRelay Scam: Tap Your Card, Lose Your Money

WindRelay Scam: Tap Your Card, Lose Your Money

Researchers say criminals are using a two-part Android malware setup (SpyNote + WindRelay) to trick victims into turning their own phones into NFC “relays” for contactless payment fraud. Victims are lured via phishing/smishing/vishing to install a malicious app, then persuaded on a live call to tap…

August 17, 2026
Fake Bank Call Triggers “Ghost Tapping” Card Fraud

Fake Bank Call Triggers “Ghost Tapping” Card Fraud

Researchers described a real scam where criminals impersonated a bank on a phone call to trick a victim into installing a malicious Android app. The attackers then remotely controlled the phone and guided the victim to tap their payment card and enter their PIN, allowing real-time contactless fraud…

August 13, 2026
Bank Imposter Calls Trick Victims Into NFC Card Relay

Bank Imposter Calls Trick Victims Into NFC Card Relay

Researchers reported a real-world phone scam where criminals impersonated a victim’s bank and coached the victim into installing an Android app. The installed remote-access malware let the fraudster silently add a second NFC relay app that streamed the victim’s payment card data to a fake terminal,…

August 14, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
BlackFile Vishing Poses as IT Support to Extort Firms

BlackFile Vishing Poses as IT Support to Extort Firms

Researchers say the BlackFile extortion group is actively targeting large financial and other organizations using voice-phishing calls where attackers impersonate IT support to get initial access. Victims are then pressured with multimillion-dollar extortion demands and, in some cases, escalations…

August 17, 2026