Infosecurity

One Phone Call, Two Malware Strains: How WindRelay and SpyNote Turned a 13-Minute Call Into a Loan Fraud

Published

on

A 13-Minute Call That Cost a Victim Their Identity

It took just 13 minutes. One phone call, a fake bank employee on the line, and a victim who followed instructions to install a single app. By the time the call ended, a fraudster had taken out a loan in the victim’s name and relayed their card data to a fake terminal — all while keeping them engaged in conversation.

Security firm Group-IB documented the case in a technical write-up published on August 12. The researchers tracked the NFC malware as WindRelay and attributed the remote access trojan (RAT) to a variant of SpyNote. The scam is a stark reminder that NFC relay fraud is no longer just a theoretical risk — it’s a live, operational threat.

The fraudster called posing as a bank employee, claiming there was a problem with the victim’s card. Then came the pitch: install this app to fix it. The victim complied, and the nightmare began.

An App Named After Its Victim

The RAT arrived through the device’s package installer — the standard route for sideloading outside an app store. But here’s the twist: its app label carried the victim’s own name, not a generic or impersonated brand.

SpyNote ships with a builder toolkit that lets an operator set a custom app name, label, and package name. So personalization isn’t manual effort — it’s built into the tool. Group-IB said the label pointed to pre-call reconnaissance that harvested the victim’s name and phone number. That meant there was no unfamiliar app name to give the victim pause.

With the RAT active, the fraudster used its remote access to install WindRelay himself. No further action was required from the victim. Notably, no screen sharing was triggered at any point — a detail that matters for detection.

One Tap, Two Payouts

WindRelay’s permissions mapped its purpose with chilling clarity:

  • NFC — to read the card
  • INTERNET — to stream captures out live
  • READ_CONTACTS — to reach further targets
  • DUMP — unusual in a third-party app, used to inspect device state

When the victim tapped their card as instructed, the malware acted as a contactless reader. It captured the live exchange between chip and reader, including the one-time code generated for that transaction. That exchange was streamed to a second device held by the fraudster, which presented itself as the card to a real terminal.

But the fraudster didn’t stop there. Using the same remote access, they took out a loan through the victim’s banking app. Group-IB read this as an opportunistic add-on rather than a planned step — a quick grab while the iron was hot. Card transactions began appearing shortly after the call ended.

23 Samples, Three Countries

Group-IB linked WindRelay to 23 samples uploaded to VirusTotal between November 2025 and July 2026. The malware impersonated institutions in Czechia, Slovakia, and Slovenia — a targeted, regional campaign rather than a scattergun operation.

This isn’t an isolated incident. Ghost Tap malware has fueled a surge in remote NFC payment fraud, and this case shows the tactics are evolving. The combination of a RAT and NFC relay in a single call is a new level of sophistication.

How to Spot and Stop This Scam

Group-IB’s recommendations are practical and worth heeding:

  • Don’t treat screen-sharing detection as a proxy for remote access — this attack never used it.
  • Alert on app installations from non-official sources during an active call.
  • Flag loan disbursements that coincide with physical card transactions.

For individuals, the advice is simpler: never install an app at the direction of an unsolicited caller. Banks don’t work that way. If someone on the line claims to be from your bank and asks you to install anything, hang up and call the number on your card.

The 13-minute call is over, but the impact could last years. As NFC payment fraud grows, understanding the mechanics of attacks like this one is the first line of defense.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version