Safety note: If you believe you have installed an application during a call like this, treat the device as compromised. Contact your bank using a different phone and the number printed on your card, and ask about both card transactions and any credit taken out in your name.
Most advice about phone security assumes the attacker is trying to get past you. This one goes through you, politely, over the course of a phone call. Researchers at Group-IB published an analysis on August 12 of a malware pairing they call WindRelay, used in fraud campaigns against people in Czechia, Slovakia and Slovenia.1
The mechanism is unusually direct. The victim is persuaded to hold their own bank card against their own phone. The phone reads the card over NFC and forwards what it reads, in real time, to a device the criminal is holding against a payment terminal or a contactless-capable cash machine somewhere else entirely.1,2
Nothing is stolen in the ordinary sense. The card never leaves the victim's hand. The tap happens where the victim is standing, and the purchase happens where the fraudster is standing, at the same moment.1,3
How the call actually goes
The scheme starts with a phone call from someone claiming to be the victim's bank, reporting a problem with the card. Group-IB's reconstruction of one case describes a call lasting about thirteen minutes, which is enough time to walk a worried person through several steps without leaving them space to stop and check.1
During the call the victim is guided into installing an app themselves. That app is SpyNote, a remote access trojan. Group-IB notes that its builder toolkit lets the operator customise the app label and name for each target, so what appears on screen can carry the victim's own name or something that looks like their bank.1,2
With remote access established, the attacker installs the second component without the victim seeing it. Then comes the instruction that makes the whole thing work: hold your card to the back of the phone, so we can verify it. The card data is captured and relayed live.1,2
Why this design is worth understanding
Card fraud usually involves stolen numbers used later, which gives banks a window to spot a pattern. A relay collapses that window. The transaction carries the characteristics of a genuine contactless tap because it is one, just performed at a distance from the person who owns the card.1,3
Group-IB reports that the pairing is monetised twice, through card-present purchases and by taking out loans in the victim's name using the remote access already established on the device. The two halves of the attack support each other, which is what makes the combination worse than either part.1,2
The research traced 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026, with impersonations localised for each target country. Group-IB's own telemetry puts NFC-based Android attacks up 188 percent in early 2026 against 2025, with 35,600 attacks blocked in the first four months of the year. Those numbers are the company's and describe what its systems saw, not a national total.1
What actually protects you
This is one of the rare cases where the defence is a rule rather than a product. Every version of the attack depends on the victim performing two actions under instruction from a caller, and both are refusable.1
- A bank will not call you and ask you to install an application. That request, from anyone, on any call, is the end of the conversation.
- A bank will not ask you to hold your card to your phone to verify it. There is no legitimate procedure that works this way.
- Hang up and call back on the number printed on the card or on the bank's official app. Do not use a number the caller gives you, and do not use the number that appeared on your screen.
- Treat an app whose name includes your own name as a warning sign. Group-IB found that personalisation used deliberately to build trust.
- If you have already installed something during such a call, put the phone in airplane mode, contact the bank from a different device, and expect to have the phone examined rather than assuming a deletion is enough.
The uncomfortable part
Group-IB says no apps containing this malware were found on Google Play, and that Android users are automatically protected against known versions by Play Protect, which is on by default. Both statements are worth reading precisely. Known versions is doing real work in that sentence, and the delivery route was never the store to begin with.1,2
The victims in these campaigns did not fail a technical test. They answered a phone call, believed a plausible person, and followed instructions during a moment of manufactured urgency about their own money. That is a social problem wearing a technical costume, and it is why the fix lives in a habit rather than in a settings menu.1,3
It is also why telling people to keep their phone updated is not much of an answer here. The malware arrives because the owner installs it. Updates matter, and they do not address the thirteen minutes in which someone is talked into it.1
Sources and method
Group-IB published its analysis on August 12 and describes samples, victim countries and a reconstructed case. The figures for attack growth and blocked attacks are Group-IB's own telemetry and are attributed as such rather than independently verified here. BleepingComputer and Help Net Security examined the research separately on August 14. Google's statement that Play Protect covers known versions is reported by Group-IB and the trade press; we did not test it.
- Gone with the WindRelay: a new malware combo behind a growing fraud scheme Group-IB · August 12, 2026 · primary
- Android malware combo takes out loans and relays victims' credit cards BleepingComputer · August 14, 2026 · independent
- New Android malware relays bank cards to fraudsters while victims still hold them Help Net Security · August 14, 2026 · independent