WindRelay Scam: Tap Your Card, Lose Your Money

The Hacker News · High sophistication
Last updated August 17, 2026

Researchers say criminals are using a two-part Android malware setup (SpyNote + WindRelay) to trick victims into turning their own phones into NFC “relays” for contactless payment fraud. Victims are lured via phishing/smishing/vishing to install a malicious app, then persuaded on a live call to tap their payment card to the infected phone under a fake “verification/PIN change” pretext, enabling real-time fraudulent transactions.

Key findings

  • WindRelay is an Android NFC relay malware used with the SpyNote RAT to enable contactless payment fraud in real time.
  • Attacks start by luring victims via phishing/smishing/vishing into sideloading a malicious app; SpyNote is then used to silently install/activate the NFC relay component.
  • The malicious APK delivered during the call is personalized with the victim’s name, suggesting pre-call reconnaissance to make the pretext more convincing.
  • Victims are coached to tap their physical card against their infected phone under a fake “identity verification / PIN change / account compromise” story, turning the phone into a payment proxy.
  • Group-IB observed WindRelay samples impersonating financial institutions in Czechia, Slovakia, and Slovenia, and described a dual-monetization approach (digital loan + card-present purchases).

Who’s being targeted

  • Commonly targeted roles: All employees (mobile-device users), Finance and Accounting, Executives and corporate cardholders, Customer support / call center teams (to recognize and warn about this fraud pattern).
  • Affected industries: Banking, Financial services, Payment card issuers.
  • Attack channels: vishing, smishing.
  • Impersonated: Victim’s bank / financial institution (bank fraud team), Bank / card issuer or “account security” service.

Awareness takeaways

  • Treat any request to install/sideload an app during an unsolicited “bank security” contact as a likely scam; stop and call the bank back using a known number.
  • Never tap your payment card to your phone because someone on a call/text told you to, banks don’t verify identity this way.
  • Be skeptical of multi-step “one session” fraud that combines a live call plus remote device control; modern scams bundle methods to move faster than detection.

Red flags to watch for

  • Unsolicited call claiming urgent account compromise
  • Request to install/sideload an app sent during a call (APK)
  • Request to tap your card to your phone as part of “verification”
  • Banking-related urgency pushing immediate install
  • App not installed from official app store (sideloading)
  • Permission prompts that enable accessibility/remote control
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: you tap your card on your own phone, and someone else goes shopping with it in real time. Scammers use WindRelay and SpyNote on Android to do exactly that. They call as “bank security,” send you a personalized APK with your name, and walk you through installing a fake verification app. On the live call they say, “Tap your card to your phone so we can verify your identity or change your PIN.” The instant you tap, your phone becomes an NFC relay, and they can run real contactless payments somewhere else. If anyone claiming to be your bank ever asks you to install an app or tap your card to your phone, hang up and call the bank back using the number on your card.

Similar attacks

Fake Bank Calls Trick Victims Into NFC Card Fraud

Fake Bank Calls Trick Victims Into NFC Card Fraud

Researchers described a real scam where criminals called victims pretending to be bank support and convinced them to install a “legitimate” Android app. The app was actually SpyNote malware, giving the attacker remote control of the phone, after which a second tool (WindRelay) was used to relay…

August 14, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake Google Play Pages Push Spyware at Logistics

Fake Google Play Pages Push Spyware at Logistics

A real campaign is targeting logistics firms with fake Google Play pages impersonating well-known logistics brands to trick employees into installing an Android spyware app. Once installed, the spyware can steal newly received SMS messages (including one-time passcodes) and enable call forwarding,…

September 24, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026