Back to news
Cybersecurity Alert
August 17, 2026 by EmailMeNow IT Consulting

WindRelay: A 13-Minute Bank Call Sideloads Android Malware and Relays Your Card

Group-IB: SpyNote RAT plus WindRelay NFC relay in a live bank-impersonation call. Sideload is the install. Audits (ideal 100%): chase.com 79%, malwarebytes.com 71%, bankofamerica.com 53%. YubiKey does not stop a RATted phone.

Source: Group-IB · Malwarebytes · BleepingComputer

NewsSocial EngineeringAndroidBanking FraudMFAYubiKeyAuthenticator AppsCybersecurity
Person on a phone call with an Android install-unknown-app prompt on screen

Group-IB documented a live-call fraud combo: SpyNote (a remote-access Trojan) plus WindRelay (NFC relay malware that forwards a contactless card tap in real time). Malwarebytes and BleepingComputer repeated the same case: a 13-minute “bank” call, a sideloaded app, a loan in the victim’s own banking app, then a card tap and PIN.

This is not a duplicate of FaceTime bank scams. FaceTime often needs no malware — the thief watches the screen. WindRelay needs the victim to install an Android package outside Google Play and grant Accessibility. Group-IB’s observed samples impersonated institutions in Czechia, Slovakia, and Slovenia. The call + sideload + tap-your-card pattern is what U.S. Android users and Texas staff need to refuse. Do not treat this as a named U.S. bank breach.

Person on a phone call with an Android install-unknown-app prompt on screen

Snapshot

FieldDetail
ResearchersGroup-IB (Aug 2026); Malwarebytes recap Aug 13
ChannelLive voice call impersonating a bank
InstallSideloaded APK (app label can include the victim’s name)
MalwareSpyNote RAT, then silent WindRelay NFC relay
Cash-outRemote use of the real bank app and live contactless relay
Observed geoCzechia, Slovakia, Slovenia (languages / brands in samples)
CourtListenerNo matching Texas or nationwide RECAP docket (searched Aug 17, 2026)

How the call works (high level)

Do not follow these as instructions. This is what victims were talked into.

StepWhat happens
1. Call“Your card has a problem” — urgency, stay on the line
2. SideloadInstall a “bank” app from a link, not Play Store
3. PermissionsAccessibility / device-control prompts during the call
4. RATSpyNote lets the caller drive the phone without screen share
5. Second payloadWindRelay is installed quietly
6. Dual theftLoan in the real bank app and “tap your card, enter PIN”

Contactless cards use one-time cryptograms. That is why the relay has to be live. A stolen static card number is a different crime. Hang up before any of this starts.

Contactless card tapped on a phone during a call while a distant terminal authorizes

What to do (Android + banking)

  1. Hang up. Call the number on the back of the card or in the official app you already had.
  2. Banks do not ask you to install an APK, enable Install unknown apps, or turn on Accessibility to “secure” a card.
  3. Install banking apps only from Google Play (or the bank’s published store listing you typed yourself).
  4. Do not tap a payment card to your phone because a caller asked. Do not read a PIN to anyone.
  5. If you already installed something: use a second device to freeze cards and call fraud. Do not keep following the first caller’s script.

BleepingComputer notes SpyNote families can also steal Google Authenticator codes, SMS, and credentials from the infected handset. Treat that phone as hostile until it is rebuilt.

MFA: YubiKey and Google Authenticator vs a RATted phone

Phishing-resistant MFA still matters for new logins on a clean computer. It does not stop an attacker who already controls the unlocked phone and the open banking app.

PlatformDirectory gradeDocumented methodsLimits in this scam
Bank of AmericaStrongFIDO USB security key for online bankingKey on a clean PC helps web login; not a RATted phone session
ChaseFailPasskeys on chase.com; phone/email OTP still documentedSMS OTP is SIM-swap class; a RAT can use the open app anyway
Google AccountStrongPasskeys, YubiKey-class keys, Google AuthenticatorAuthenticator on the infected phone can be stolen

Directory rows: MFA support directory · BofA USB security key · Chase how you can protect yourself · Google passkeys / Authenticator.

Prefer a hardware key on a computer that did not install the APK. Do not use SMS as the only bank factor. See the national banks MFA scorecard.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
YubiKey 5 / 5C NFC caseKeychain protection for the keyAmazon
Proton PassPasskeys + authenticator-style TOTP vaultProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key beside an authenticator phone and a note that TOTP on a RATted device can be stolen

Independent cybersecurity audits

We audited researcher, Play-ecosystem, and U.S. bank hosts on August 17, 2026. 100% is the idealnone reach it. These scores are public email / transport / website posture. They do not tell you whether a caller is your bank.

OrganizationDomainOverallIdentityTransportWebsitevs 100%
Chasechase.com79%75%15%94%−21
Malwarebytesmalwarebytes.com71%90%45%43%−29
Group-IBgroup-ib.com60%30%15%92%−40
Googlegoogle.com55%50%70%37%−45
Bank of Americabankofamerica.com53%50%45%37%−47

Audit links: chase.com · malwarebytes.com · group-ib.com · google.com · bankofamerica.com

Domain audit scoreboard versus the 100 percent ideal

Website stack note

Passive website-tech probes on August 17, 2026:

DomainStack signal
group-ib.comPHP 8.2.33 (supported through ~2026-12-31)
malwarebytes.comWordPress, generator version hidden
chase.comNext.js; CT certificate expires 2026-09-11 (~25 days)
google.comNo notable CMS flag
bankofamerica.comNo notable CMS flag

Point-in-time only. A clean bank website does not make a cold call legitimate.

Blacklist and lookalike domains

Email blacklist checks (public DoH, August 17, 2026): group-ib.com, malwarebytes.com, google.com, chase.com, and bankofamerica.com were clear on mail/domain lists we can query. Chase web/CDN IPs showed informational SPFBL notes — not a reason to click “Chase security” mail. Type chase.com yourself.

DNS lookalike scans (registered DNS signals only, not WHOIS authority):

Brand scannedTo reviewLikely ownedBEC staging
chase.com9602
bankofamerica.com175131
group-ib.com2352

High-interest registered names (investigate; not proof this campaign used them):

LookalikeTechniqueNote
chase.io / chasen.comtld-swap / insertionChase BEC staging (NS, MX)
chase.apptld-swapApp-themed TLD — still not the Play Store
bankofamer1ca.comhomoglyphBofA BEC staging (NS, MX)
groupib.com / group-ib.codehyphen / tld-swapGroup-IB BEC staging (NS, MX)

Many bankofamerica.* TLD swaps already redirect to Bank of America. Continuous monitoring: Cybersquat Domain Monitoring.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for mobile MDM and phishing response aimed at the 100% ideal.


Sources: Group-IB — WindRelay / SpyNote · Malwarebytes, Aug 13, 2026 · BleepingComputer, Aug 12, 2026 · Help Net Security · Bank of America USB security key · Chase security · Google passkeys. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches August 17, 2026. Domain scores: audit.emailmenow.com only.