# Two Malware, One Victim: How WindRelay and SpyNote Are Draining Bank Accounts in Real Time
The victim never saw it coming. Their phone was infected, their contactless payment data was being relayed live to a criminal holding a separate Android device across the city, and somewhere in the background, a loan application was being quietly submitted in their name. By the time the fraud alerts hit, the damage was done across at least three attack surfaces simultaneously.
That's the architecture of the campaign researchers have now documented pairing WindRelay, a newly identified NFC relay malware, with SpyNote, one of the most battle-tested Android remote administration tools in active criminal use. This isn't two malware samples that happen to share a victim — it's a deliberately integrated operation that treats the compromised device as both a surveillance asset and a physical payment terminal to be exploited at will.
## The Relay That Shouldn't Be Possible
NFC relay attacks sound exotic. They're not anymore.
Here's the mechanic: WindRelay captures the NFC signals from the victim's payment cards — or more precisely, the device's NFC hardware reading those cards — and transmits that data in real time to an attacker-controlled device. The attacker's device then emulates the card at a point-of-sale terminal. The transaction completes. The money moves. The victim's phone just funded a purchase they never made, at a location they've never been.
This technique has appeared before. ESET documented NGate in mid-2024, which used a similar NFC relay approach to cash out at ATMs. SuperCard X followed in early 2025, expanding the model to broader POS fraud. WindRelay appears to be the next iteration — refined, and critically, now bundled with a RAT rather than deployed as a standalone tool.
The pairing with SpyNote is what separates this campaign from its predecessors. SpyNote isn't new — it's been circulating in various forms since at least 2022, offered as crimeware-as-a-service with capabilities including keylogging, screen recording, microphone access, camera activation, and SMS interception. Security teams have been tracking SpyNote campaigns targeting bank customers across Europe, South Asia, and Latin America for years.
What SpyNote adds to WindRelay's NFC relay capability is devastating context: attackers aren't just skimming a card signal blind. They can see the victim's banking apps, capture credentials, bypass SMS-based two-factor authentication in real time, and — this is the loan vector — navigate financial applications with full visibility into the victim's account standing, credit history, and personal details as the victim has entered them.
## The Loan Fraud Is the Larger Score
Media coverage of NFC relay attacks tends to fixate on the card-skimming angle because it's viscerally easy to understand. But the loan origination fraud documented in this campaign is probably the larger financial exposure.
Here's why: contactless payment fraud has a ceiling. Card issuers impose contactless transaction limits — typically £100 in the UK, varying elsewhere — and POS fraud triggers velocity checks quickly. A criminal relay team might successfully run a handful of transactions before the card gets flagged.
A fraudulently originated personal loan, on the other hand, can run to tens of thousands of dollars. And with SpyNote providing full device access — reading documents, capturing screen content, watching the victim navigate their banking apps — the attackers have everything they need: identity documents, income figures the victim themselves has entered into an app, and the ability to intercept the OTP that finalizes the application.
This is a convergence of three historically separate fraud categories — card-present fraud, account takeover, and synthetic/application fraud — executed from a single compromised device. That's a meaningful escalation.
## The SpyNote Distribution Problem
SpyNote typically lands through social engineering: fake app store listings, sideloaded APKs delivered via phishing SMS or Telegram, fake utility apps, fake "security updates." The campaign's effectiveness depends entirely on getting the victim to grant the Accessibility Service permissions that SpyNote needs to function.
This is Android's chronic blind spot. Accessibility Services are a legitimate API — designed to assist users with disabilities — that provides near-complete device control to any app granted permission. Google has been tightening restrictions here since Android 13, but the permission still exists, users still grant it when prompted convincingly, and malicious apps still exploit it routinely.
The victims most at risk aren't necessarily unsophisticated users. SpyNote campaigns have repeatedly targeted people who were specifically seeking financial apps, loan applications, or tax utilities — contexts where granting unusual permissions doesn't immediately seem alarming. A fake loan app that installs SpyNote and then offers to "help" the user apply for credit has a certain grim elegance: the malware's cover story and its actual payload are the same thing.
## What Defenders — and Everyone Else — Should Do Right Now
For enterprise security teams managing Android fleets, the immediate action is straightforward:
For individuals: the hard truth is that Android's openness is also its attack surface. Sideloading apps — installing APKs from outside the Play Store — remains the primary vector for campaigns like this. That means the security guidance hasn't changed much: don't sideload from untrusted sources, be aggressive about rejecting Accessibility permission requests from apps that don't obviously need them, and enable transaction notifications from your bank so NFC fraud shows up in seconds rather than days.
---
## HackWire Analysis
The WindRelay/SpyNote pairing is less a new invention than a maturation of a technique the criminal ecosystem has been building toward for two years.
What the NGate → SuperCard X → WindRelay progression shows is systematic capability development. Each iteration has refined the relay mechanism, added robustness against detection, and expanded the monetization surface. The addition of a capable RAT like SpyNote to this toolchain suggests the operators understand that card relay alone is a commodity attack with limited ceiling — full device access is worth more.
The underreported angle here is the infrastructure question. NFC relay attacks require coordination: one device (the "reader") near the victim harvesting the NFC signal, another device (the "emulator") at the point of sale making the transaction. That's a two-person operation, or at minimum a two-device setup with real-time communication between them. The campaigns running this successfully aren't lone wolves — they're organized, and they're operating in jurisdictions where financial fraud prosecution is slow or absent.
This also matters for the fintech sector specifically. The same "speed of credit" that makes modern consumer lending apps appealing — loan approval in minutes, minimal friction — is precisely what the SpyNote loan fraud vector exploits. Lenders who have optimized for conversion have done so partly by reducing the friction that would catch this attack. The industry has been aware of account takeover as a threat; the combination with live device surveillance makes that threat significantly harder to defend against at the application layer.
The banking sector should treat this campaign as a stress test of their behavioral biometrics and out-of-band verification controls. If a loan application is being navigated by an attacker with full screen visibility and SMS interception, those controls may not be sufficient.
— HackWire Editorial
---
## Related Coverage