WindRelay NFC relay malware deployed with SpyNote RAT
Malware Activity
Summary
Hide ▲
Show ▼
The WindRelay malware chain turned a 13-minute phone call into live card fraud, relaying a victim’s card data to a fake terminal and helping an operator take out a loan in the victim’s name. The activity paired WindRelay with SpyNote RAT to gain remote access on Android devices and install the relay tool while the victim stayed on the line. Group-IB linked the malware to 23 samples uploaded between November 2025 and July 2026, with impersonation themes tied to institutions in Czechia, Slovakia and Slovenia.
Related Happenings
Android tap-to-pay malware relays NFC card data for fraudulent payments
Malware Activity
H score30
First: 07.01.2026 18:00
Last: 07.01.2026 18:00
Sources 1
About this happening:
A wave of Android tap-to-pay malware is enabling unauthorized contactless payments by relaying NFC card data from victims’ phones to criminal devices. The operation us...
Android tap-to-pay malware relays NFC card data for fraudulent payments
Malware ActivityAbout this happening: A wave of Android tap-to-pay malware is enabling unauthorized contactless payments by relaying NFC card data from victims’ phones to criminal devices. The operation us...
Wonderland Android SMS stealer activity targeting Uzbekistan
Malware Activity
H score27
First: 22.12.2025 08:11
Last: 22.12.2025 08:11
Sources 1
About this happening:
The Wonderland Android SMS stealer is being spread through malicious droppers in attacks targeting users in Uzbekistan, enabling SMS and OTP theft and bank-card fr...
Wonderland Android SMS stealer activity targeting Uzbekistan
Malware ActivityAbout this happening: The Wonderland Android SMS stealer is being spread through malicious droppers in attacks targeting users in Uzbekistan, enabling SMS and OTP theft and bank-card fr...
Timeline
-
12.08.2026 17:30 2 articles · 1h ago
Group-IB documents WindRelay and SpyNote live-call NFC relay fraud
Initial DisclosureGroup-IB described WindRelay, a previously unseen NFC relay malware family used with a SpyNote RAT in a 13-minute live-call scam, where a fraudster posed as a bank employee, used remote access to install WindRelay, captured the chip-and-reader exchange when the victim tapped a card, relayed the data to a fake terminal, and used the same access to take out a loan in the victim's banking app. Group-IB also linked WindRelay to 23 VirusTotal samples uploaded between November 2025 and July 2026 that impersonated institutions in Czechia, Slovakia and Slovenia.
Show sources
- WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam — www.infosecurity-magazine.com — 12.08.2026 17:30
- WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam — www.infosecurity-magazine.com — 12.08.2026 17:30