WindRelay And SpyNote Pair Drives Android Phone Fraud Workflow
BleepingComputer reported that Group-IB investigated a WindRelay and SpyNote Android malware combination that used social engineering, remote device access and NFC relay fraud to move from a phone call to financial theft.

BleepingComputer reported that Group-IB investigated an Android fraud case in which WindRelay NFC relay malware worked alongside the SpyNote remote administration tool to turn a victim's phone into part of a live payment-abuse workflow.
The case is notable because the theft did not depend on a new banking-app exploit.
A caller impersonating a bank employee persuaded the victim to install a malicious Android app, after which SpyNote gave the fraudster remote control of the device and WindRelay supplied the payment relay channel.
Group-IB said the whole incident took place during a 13-minute phone call.
That short window was enough for the attacker to gain device access, open a loan through the banking app under the victim's identity, then relay payment-card data for purchases approved with the victim's PIN.
The malware pairing shows why mobile-fraud defenses cannot treat device takeover and payment abuse as separate problems.
SpyNote provided access to the handset and banking session, while WindRelay created the cash-out path by relaying a live contactless card interaction to equipment controlled by the attacker.
The same pattern also narrows the user-protection lesson.
The most important decision point came before the malware ran, when the victim was pressured by phone to trust the caller, install an app from outside normal channels and grant sensitive Android permissions.
Group-IB connected the toolkit to nearly 24 WindRelay submissions to VirusTotal from November 2025 through July 2026.
The samples communicated with four command-and-control IP addresses, giving defenders infrastructure and file evidence to hunt without needing to reproduce the fraud flow.
The targeting evidence remains regional rather than global in the public account.
Group-IB linked the activity mainly to Czechia, Slovakia and Slovenia, based on impersonated organizations and the languages used in the lures.
SpyNote's longer history raises the operational risk for banks and mobile-security teams.
Variants including SpyMax and CypherRAT have circulated since at least 2021, and detections increased in late 2022 and early 2023 after the malware's source code leaked.
The practical control point is still verification and permission discipline.
Android users should avoid APKs outside Google Play unless they fully trust the publisher, treat NFC and accessibility requests as high-risk permissions, and end unsolicited bank calls before using an official number to contact the institution.




















