A sneaky combination of apps is emptying bank accounts in Slovenia too
Cybersecurity experts from Group-IB have revealed a new and extremely dangerous tactical combination of malicious tools for the Android mobile operating system. It is a combination of the well-known remote control tool SpyNote and the newer program WindRelay, which exploits NFC technology. The main goal of the attackers is to intercept bank card data in real time and take control of the victim's device.
The attack usually starts with a classic phone call. The scammer pretends to be a bank employee and convinces the victim that there is a problem with their payment card. To make the scam look as convincing as possible, the attacker sends the victim a customized application that even includes their name. Once the user manually installs this application and grants it access to accessibility services, the scammer gains complete remote control of the phone.
In the next step, the attacker installs the WindRelay tool on the phone without the user’s knowledge and applies for a loan on behalf of the victim via a banking app. The victim is then instructed to hold their physical bank card up to the phone and enter their PIN. At this point, WindRelay turns the phone into a fake card reader. All contactless transaction data, including security information, is transmitted in real time to the attacker’s device, who can then use this data to make purchases at a real payment terminal or even withdraw cash.
Interestingly, the attackers don't need complex screen sharing or live streaming to carry out the entire scam, but rely entirely on psychological pressure during a phone conversation. The SpyNote tool, which has been around since 2021, is capable of stealing passwords, intercepting SMS messages, two-factor authentication codes, and even turning on the microphone and camera.
Security analysts have recorded nearly two-tenths of WindRelay samples between November 2025 and July 2026. Based on the language used and the bank brands that the attackers are imitating, the primary targets of this wave of attacks are users in the Czech Republic, Slovakia, and Slovenia.



















