WindRelay and SpyNote Fueled a 13-Minute Call Scam

Group-IB documented a 13-minute live-call fraud on August 12 that paired WindRelay NFC relay malware with a SpyNote remote access trojan (RAT), letting one operator clone a card and trigger a loan in the victim’s name during the same call. The victim was kept on the line by someone posing as a bank employee with a card problem. The fraudster talked the victim through installing a sideloaded app, then used SpyNote to take over the phone and install WindRelay. WindRelay read the card’s contactless exchange when the victim tapped it, streamed that data to the attacker’s other device, and that device acted as the card at a real terminal. In plain terms, the call was the cover, the phone became the reader, and the other device became the card. For banks and fraud teams, the important part is the overlap: the payment fraud and the banking fraud happened inside one live conversation, not as separate events. If your verification flow depends on a caller staying engaged while a mobile device is being ‘checked,’ that conversation itself can be the place where card data and account access are both lost.

Part of the PlainSec briefing for 2026-08-13

Every edition of this story: WindRelay and SpyNote Fueled a 13-Minute Call Scam

Sources