WindRelay Scam: Tap Your Card, Lose Your Money

The Hacker News · High sophistication
Last updated August 17, 2026

Researchers say criminals are using a two-part Android malware setup (SpyNote + WindRelay) to trick victims into turning their own phones into NFC “relays” for contactless payment fraud. Victims are lured via phishing/smishing/vishing to install a malicious app, then persuaded on a live call to tap their payment card to the infected phone under a fake “verification/PIN change” pretext, enabling real-time fraudulent transactions.

Key findings

  • WindRelay is an Android NFC relay malware used with the SpyNote RAT to enable contactless payment fraud in real time.
  • Attacks start by luring victims via phishing/smishing/vishing into sideloading a malicious app; SpyNote is then used to silently install/activate the NFC relay component.
  • The malicious APK delivered during the call is personalized with the victim’s name, suggesting pre-call reconnaissance to make the pretext more convincing.
  • Victims are coached to tap their physical card against their infected phone under a fake “identity verification / PIN change / account compromise” story, turning the phone into a payment proxy.
  • Group-IB observed WindRelay samples impersonating financial institutions in Czechia, Slovakia, and Slovenia, and described a dual-monetization approach (digital loan + card-present purchases).

Who’s being targeted

  • Commonly targeted roles: All employees (mobile-device users), Finance and Accounting, Executives and corporate cardholders, Customer support / call center teams (to recognize and warn about this fraud pattern).
  • Affected industries: Banking, Financial services, Payment card issuers.
  • Attack channels: vishing, smishing.
  • Impersonated: Victim’s bank / financial institution (bank fraud team), Bank / card issuer or “account security” service.

Awareness takeaways

  • Treat any request to install/sideload an app during an unsolicited “bank security” contact as a likely scam; stop and call the bank back using a known number.
  • Never tap your payment card to your phone because someone on a call/text told you to, banks don’t verify identity this way.
  • Be skeptical of multi-step “one session” fraud that combines a live call plus remote device control; modern scams bundle methods to move faster than detection.

Red flags to watch for

  • Unsolicited call claiming urgent account compromise
  • Request to install/sideload an app sent during a call (APK)
  • Request to tap your card to your phone as part of “verification”
  • Banking-related urgency pushing immediate install
  • App not installed from official app store (sideloading)
  • Permission prompts that enable accessibility/remote control
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: you tap your card on your own phone, and someone else goes shopping with it in real time. Scammers use WindRelay and SpyNote on Android to do exactly that. They call as “bank security,” send you a personalized APK with your name, and walk you through installing a fake verification app. On the live call they say, “Tap your card to your phone so we can verify your identity or change your PIN.” The instant you tap, your phone becomes an NFC relay, and they can run real contactless payments somewhere else. If anyone claiming to be your bank ever asks you to install an app or tap your card to your phone, hang up and call the bank back using the number on your card.

Similar attacks

Fake Bank Calls Trick Victims Into NFC Card Fraud

Fake Bank Calls Trick Victims Into NFC Card Fraud

Researchers described a real scam where criminals called victims pretending to be bank support and convinced them to install a “legitimate” Android app. The app was actually SpyNote malware, giving the attacker remote control of the phone, after which a second tool (WindRelay) was used to relay…

August 14, 2026
Bank Imposter Calls Trick Victims Into NFC Card Relay

Bank Imposter Calls Trick Victims Into NFC Card Relay

Researchers reported a real-world phone scam where criminals impersonated a victim’s bank and coached the victim into installing an Android app. The installed remote-access malware let the fraudster silently add a second NFC relay app that streamed the victim’s payment card data to a fake terminal,…

August 14, 2026
Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026
Fake IRS Letters and BoA Emails Push Remote Access Scams

Fake IRS Letters and BoA Emails Push Remote Access Scams

This weekly roundup includes real-world social engineering campaigns, including scammers mailing fake IRS letters to cryptocurrency holders and a phishing campaign impersonating Bank of America. The lures are designed to pressure victims into visiting a bogus compliance portal or installing remote…

August 9, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
Fake iPhone Crypto Wallet Stole $1.8M

Fake iPhone Crypto Wallet Stole $1.8M

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users into entering their wallet recovery phrase, then criminals used it to drain about $1.8 million in Bitcoin. The case highlights how…

July 29, 2026