Fake Bank Calls Trick Victims Into NFC Card Fraud

eSecurity Planet · High sophistication
Last updated August 17, 2026

Researchers described a real scam where criminals called victims pretending to be bank support and convinced them to install a “legitimate” Android app. The app was actually SpyNote malware, giving the attacker remote control of the phone, after which a second tool (WindRelay) was used to relay live NFC (tap-to-pay) transactions and steal money within minutes.

How the Attack Worked

This attack, documented by Group-IB, began with a phone call. The caller impersonated bank support staff and convinced the victim that an account issue needed to be resolved by installing an app. That app was a customized version of the SpyNote Android remote access trojan, personalized with the victim's own name to appear credible. Because it was sideloaded from outside Google Play, the victim also had to be talked into granting the Android Accessibility Service permission, which gave the attacker the ability to view and control the device's screen remotely.

Once the attacker had remote control, they deployed a second tool, WindRelay, to relay live NFC (tap-to-pay) transactions. According to Group-IB, the entire sequence, from the initial support call to a completed live NFC fraud transaction, took about 13 minutes. Attackers reportedly also took out a loan in the victim's name as part of the broader fraud.

Why It Succeeded

The scheme worked because it layered several trust-building steps on top of each other:

  • A phone call created urgency and an appearance of legitimate bank contact.
  • Personalizing the malicious app with the victim's name reduced suspicion.
  • Framing the install and permission request as necessary steps to "fix" an account issue made the requests feel routine rather than alarming.
  • Once remote access and Accessibility permissions were granted, the victim had little visibility into what was actually happening on their device.

What to Watch For

Key red flags identified in this attack pattern include:

  • A caller claiming to be bank support who asks you to install an app from outside the official app store.
  • Requests to enable Android Accessibility Service permissions for an app you did not seek out yourself.
  • Pressure to act quickly during an unsolicited support call.
  • Being instructed to use your payment card as part of a "support" process.
  • Unexpected financial activity, such as a loan appearing in your name that you did not initiate.

Building Resistance

Awareness efforts should reinforce a few concrete habits. Treat unsolicited bank support calls with suspicion, and instead hang up and call back using the number on the back of your card or the bank's official website. Only install apps from official stores such as Google Play, never based on instructions from a phone call. Be cautious about granting Accessibility permissions, since this level of access can enable full remote control of a device. Finally, remember that a legitimate bank representative should never need you to sideload an app, grant special device permissions, or use your payment card to resolve a support issue. These habits directly counter each step used in this real-world attack chain.

Key findings

  • Attackers used fake bank support phone calls to persuade victims to install a malicious Android app.
  • The initial app was a customized SpyNote Android RAT, personalized with victim details (e.g., the victim’s name) to appear credible.
  • Victims were convinced to sideload the app (outside Google Play) and grant Accessibility permissions, enabling remote control.
  • After compromise, attackers remotely installed WindRelay and used it to relay live NFC transactions, enabling contactless card fraud.
  • Group-IB reported the end-to-end conversion from support call to live NFC fraud took about 13 minutes.
  • Attackers also conducted conventional banking fraud steps such as taking out a loan in the victim’s name.

Who’s being targeted

  • Commonly targeted roles: All staff (mobile device users), Finance / cardholders (corporate card users), Executives (high-value targets for fraud), Customer support teams (to recognize and warn about callback scams).
  • Affected industries: Banking/Financial services, Consumers/retail banking customers.
  • Attack channels: vishing.
  • Impersonated: Bank support / bank representative.

Red flags to watch for

  • Caller asks you to install an app outside the official app store
  • Caller asks for Android Accessibility Service permissions
  • Pressure to act immediately during a “support” call
  • Being told to use your payment card as part of “support”
  • Unexplained urgency and scripted instructions while on the phone
  • Unexpected financial activity such as a loan opened in your name
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers trick victims into installing malware?

Attackers called victims pretending to be bank support and convinced them to sideload a customized Android app that was actually the SpyNote remote access trojan.

What made the malicious app seem trustworthy?

The SpyNote app was personalized with the victim's own name, which made it appear legitimate during the phone call.

How fast did the fraud happen once the app was installed?

Group-IB reported that the end-to-end process from the initial support call to live NFC fraud took about 13 minutes.

What permission did the attackers need to control the phone remotely?

They persuaded victims to grant the Android Accessibility Service permission, which let the attacker view and control screen content remotely.

Read the video transcript

Imagine this: a “bank support” call, and 13 minutes later, your Android is running live tap-to-pay fraud. Researchers saw this: caller pretends to fix an issue, walks the victim through installing a “support” app that’s actually SpyNote, sideloaded outside Google Play, then tricks them into granting Android Accessibility so they can drive the phone remotely. Once SpyNote is in, they push WindRelay, tell the victim to 'make a test payment,' and relay live NFC transactions in the background, plus classic fraud like taking out a loan in the victim’s name. Here’s your move: if “bank support” ever asks you to install an app or use your card on that call, hang up and call the number on the back of your card instead.

Similar attacks

Fake Bank Call Triggers “Ghost Tapping” Card Fraud

Fake Bank Call Triggers “Ghost Tapping” Card Fraud

Researchers described a real scam where criminals impersonated a bank on a phone call to trick a victim into installing a malicious Android app. The attackers then remotely controlled the phone and guided the victim to tap their payment card and enter their PIN, allowing real-time contactless fraud…

August 13, 2026
Bank Imposter Calls Trick Victims Into NFC Card Relay

Bank Imposter Calls Trick Victims Into NFC Card Relay

Researchers reported a real-world phone scam where criminals impersonated a victim’s bank and coached the victim into installing an Android app. The installed remote-access malware let the fraudster silently add a second NFC relay app that streamed the victim’s payment card data to a fake terminal,…

August 14, 2026
Fake IT Help Desk Calls Hit Private Equity

Fake IT Help Desk Calls Hit Private Equity

Researchers say a threat group tracked as UNC6671 is calling employees and posing as IT help desk staff to steal login credentials and multi-factor authentication (MFA) tokens. After gaining access, the attackers reportedly exfiltrate large amounts of corporate data and then issue extortion…

August 11, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
Govt-Themed Phishing Spreads Cruciferra Malware

Govt-Themed Phishing Spreads Cruciferra Malware

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a “crypter” service called Cruciferra to help common remote-access and data-stealing malware evade detection. Financial services, healthcare,…

July 21, 2026