Group-IB documented a live-call fraud combo: SpyNote (a remote-access Trojan) plus WindRelay (NFC relay malware that forwards a contactless card tap in real time). Malwarebytes and BleepingComputer repeated the same case: a 13-minute “bank” call, a sideloaded app, a loan in the victim’s own banking app, then a card tap and PIN.
This is not a duplicate of FaceTime bank scams. FaceTime often needs no malware — the thief watches the screen. WindRelay needs the victim to install an Android package outside Google Play and grant Accessibility. Group-IB’s observed samples impersonated institutions in Czechia, Slovakia, and Slovenia. The call + sideload + tap-your-card pattern is what U.S. Android users and Texas staff need to refuse. Do not treat this as a named U.S. bank breach.

Snapshot
| Field | Detail |
|---|---|
| Researchers | Group-IB (Aug 2026); Malwarebytes recap Aug 13 |
| Channel | Live voice call impersonating a bank |
| Install | Sideloaded APK (app label can include the victim’s name) |
| Malware | SpyNote RAT, then silent WindRelay NFC relay |
| Cash-out | Remote use of the real bank app and live contactless relay |
| Observed geo | Czechia, Slovakia, Slovenia (languages / brands in samples) |
| CourtListener | No matching Texas or nationwide RECAP docket (searched Aug 17, 2026) |
How the call works (high level)
Do not follow these as instructions. This is what victims were talked into.
| Step | What happens |
|---|---|
| 1. Call | “Your card has a problem” — urgency, stay on the line |
| 2. Sideload | Install a “bank” app from a link, not Play Store |
| 3. Permissions | Accessibility / device-control prompts during the call |
| 4. RAT | SpyNote lets the caller drive the phone without screen share |
| 5. Second payload | WindRelay is installed quietly |
| 6. Dual theft | Loan in the real bank app and “tap your card, enter PIN” |
Contactless cards use one-time cryptograms. That is why the relay has to be live. A stolen static card number is a different crime. Hang up before any of this starts.

What to do (Android + banking)
- Hang up. Call the number on the back of the card or in the official app you already had.
- Banks do not ask you to install an APK, enable Install unknown apps, or turn on Accessibility to “secure” a card.
- Install banking apps only from Google Play (or the bank’s published store listing you typed yourself).
- Do not tap a payment card to your phone because a caller asked. Do not read a PIN to anyone.
- If you already installed something: use a second device to freeze cards and call fraud. Do not keep following the first caller’s script.
BleepingComputer notes SpyNote families can also steal Google Authenticator codes, SMS, and credentials from the infected handset. Treat that phone as hostile until it is rebuilt.
MFA: YubiKey and Google Authenticator vs a RATted phone
Phishing-resistant MFA still matters for new logins on a clean computer. It does not stop an attacker who already controls the unlocked phone and the open banking app.
| Platform | Directory grade | Documented methods | Limits in this scam |
|---|---|---|---|
| Bank of America | Strong | FIDO USB security key for online banking | Key on a clean PC helps web login; not a RATted phone session |
| Chase | Fail | Passkeys on chase.com; phone/email OTP still documented | SMS OTP is SIM-swap class; a RAT can use the open app anyway |
| Google Account | Strong | Passkeys, YubiKey-class keys, Google Authenticator | Authenticator on the infected phone can be stolen |
Directory rows: MFA support directory · BofA USB security key · Chase how you can protect yourself · Google passkeys / Authenticator.
Prefer a hardware key on a computer that did not install the APK. Do not use SMS as the only bank factor. See the national banks MFA scorecard.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| YubiKey 5 / 5C NFC case | Keychain protection for the key | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP vault | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited researcher, Play-ecosystem, and U.S. bank hosts on August 17, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not tell you whether a caller is your bank.
| Organization | Domain | Overall | Identity | Transport | Website | vs 100% |
|---|---|---|---|---|---|---|
| Chase | chase.com | 79% | 75% | 15% | 94% | −21 |
| Malwarebytes | malwarebytes.com | 71% | 90% | 45% | 43% | −29 |
| Group-IB | group-ib.com | 60% | 30% | 15% | 92% | −40 |
| google.com | 55% | 50% | 70% | 37% | −45 | |
| Bank of America | bankofamerica.com | 53% | 50% | 45% | 37% | −47 |
Audit links: chase.com · malwarebytes.com · group-ib.com · google.com · bankofamerica.com

Website stack note
Passive website-tech probes on August 17, 2026:
| Domain | Stack signal |
|---|---|
| group-ib.com | PHP 8.2.33 (supported through ~2026-12-31) |
| malwarebytes.com | WordPress, generator version hidden |
| chase.com | Next.js; CT certificate expires 2026-09-11 (~25 days) |
| google.com | No notable CMS flag |
| bankofamerica.com | No notable CMS flag |
Point-in-time only. A clean bank website does not make a cold call legitimate.
Blacklist and lookalike domains
Email blacklist checks (public DoH, August 17, 2026): group-ib.com, malwarebytes.com, google.com, chase.com, and bankofamerica.com were clear on mail/domain lists we can query. Chase web/CDN IPs showed informational SPFBL notes — not a reason to click “Chase security” mail. Type chase.com yourself.
DNS lookalike scans (registered DNS signals only, not WHOIS authority):
| Brand scanned | To review | Likely owned | BEC staging |
|---|---|---|---|
| chase.com | 96 | 0 | 2 |
| bankofamerica.com | 175 | 13 | 1 |
| group-ib.com | 23 | 5 | 2 |
High-interest registered names (investigate; not proof this campaign used them):
| Lookalike | Technique | Note |
|---|---|---|
| chase.io / chasen.com | tld-swap / insertion | Chase BEC staging (NS, MX) |
| chase.app | tld-swap | App-themed TLD — still not the Play Store |
| bankofamer1ca.com | homoglyph | BofA BEC staging (NS, MX) |
| groupib.com / group-ib.co | dehyphen / tld-swap | Group-IB BEC staging (NS, MX) |
Many bankofamerica.* TLD swaps already redirect to Bank of America. Continuous monitoring: Cybersquat Domain Monitoring.
Related coverage
- FaceTime bank scam (iOS video; often no malware)
- National banks MFA — SMS vs YubiKey
- FBI NCII / lookalike support phishing (stolen MFA codes without a RAT)
- MFA support directory
- Texas banks MFA
Run a free audit at audit.emailmenow.com or contact EmailMeNow for mobile MDM and phishing response aimed at the 100% ideal.
Sources: Group-IB — WindRelay / SpyNote · Malwarebytes, Aug 13, 2026 · BleepingComputer, Aug 12, 2026 · Help Net Security · Bank of America USB security key · Chase security · Google passkeys. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches August 17, 2026. Domain scores: audit.emailmenow.com only.