WindRelay Scam: Tap Your Card, Lose Your Money

The Hacker News · High sophistication
Last updated August 17, 2026

Researchers say criminals are using a two-part Android malware setup (SpyNote + WindRelay) to trick victims into turning their own phones into NFC “relays” for contactless payment fraud. Victims are lured via phishing/smishing/vishing to install a malicious app, then persuaded on a live call to tap their payment card to the infected phone under a fake “verification/PIN change” pretext, enabling real-time fraudulent transactions.

Key findings

  • WindRelay is an Android NFC relay malware used with the SpyNote RAT to enable contactless payment fraud in real time.
  • Attacks start by luring victims via phishing/smishing/vishing into sideloading a malicious app; SpyNote is then used to silently install/activate the NFC relay component.
  • The malicious APK delivered during the call is personalized with the victim’s name, suggesting pre-call reconnaissance to make the pretext more convincing.
  • Victims are coached to tap their physical card against their infected phone under a fake “identity verification / PIN change / account compromise” story, turning the phone into a payment proxy.
  • Group-IB observed WindRelay samples impersonating financial institutions in Czechia, Slovakia, and Slovenia, and described a dual-monetization approach (digital loan + card-present purchases).

Who’s being targeted

  • Commonly targeted roles: All employees (mobile-device users), Finance and Accounting, Executives and corporate cardholders, Customer support / call center teams (to recognize and warn about this fraud pattern).
  • Affected industries: Banking, Financial services, Payment card issuers.
  • Attack channels: vishing, smishing.
  • Impersonated: Victim’s bank / financial institution (bank fraud team), Bank / card issuer or “account security” service.

Awareness takeaways

  • Treat any request to install/sideload an app during an unsolicited “bank security” contact as a likely scam; stop and call the bank back using a known number.
  • Never tap your payment card to your phone because someone on a call/text told you to, banks don’t verify identity this way.
  • Be skeptical of multi-step “one session” fraud that combines a live call plus remote device control; modern scams bundle methods to move faster than detection.

Red flags to watch for

  • Unsolicited call claiming urgent account compromise
  • Request to install/sideload an app sent during a call (APK)
  • Request to tap your card to your phone as part of “verification”
  • Banking-related urgency pushing immediate install
  • App not installed from official app store (sideloading)
  • Permission prompts that enable accessibility/remote control
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: you tap your card on your own phone, and someone else goes shopping with it in real time. Scammers use WindRelay and SpyNote on Android to do exactly that. They call as “bank security,” send you a personalized APK with your name, and walk you through installing a fake verification app. On the live call they say, “Tap your card to your phone so we can verify your identity or change your PIN.” The instant you tap, your phone becomes an NFC relay, and they can run real contactless payments somewhere else. If anyone claiming to be your bank ever asks you to install an app or tap your card to your phone, hang up and call the bank back using the number on your card.

Similar attacks

Fake Bank Calls Trick Victims Into NFC Card Fraud

Fake Bank Calls Trick Victims Into NFC Card Fraud

Researchers described a real scam where criminals called victims pretending to be bank support and convinced them to install a “legitimate” Android app. The app was actually SpyNote malware, giving the attacker remote control of the phone, after which a second tool (WindRelay) was used to relay…

August 14, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Bank Imposter Calls Trick Victims Into NFC Card Relay

Bank Imposter Calls Trick Victims Into NFC Card Relay

Researchers reported a real-world phone scam where criminals impersonated a victim’s bank and coached the victim into installing an Android app. The installed remote-access malware let the fraudster silently add a second NFC relay app that streamed the victim’s payment card data to a fake terminal,…

August 14, 2026
Fake IT Support Drives Pix Fraud in Brazil

Fake IT Support Drives Pix Fraud in Brazil

A financially motivated group called Breeze Comet targeted Brazilian financial and retail organizations by impersonating IT support and convincing staff to install remote-access tools. After gaining access, the attackers moved into internal payment systems (like Pix/STR/Boleto) and executed…

September 1, 2026
Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026