Find notable cyber news and cases, enriched with sources, timelines, and signals.

WindRelay NFC relay malware deployed with SpyNote RAT

Malware Activity
First reported
Last updated
Happening score
H score 19
1 unique sources, 1 articles

Summary

Hide ▲

The WindRelay malware chain turned a 13-minute phone call into live card fraud, relaying a victim’s card data to a fake terminal and helping an operator take out a loan in the victim’s name. The activity paired WindRelay with SpyNote RAT to gain remote access on Android devices and install the relay tool while the victim stayed on the line. Group-IB linked the malware to 23 samples uploaded between November 2025 and July 2026, with impersonation themes tied to institutions in Czechia, Slovakia and Slovenia.

Related Happenings

Android tap-to-pay malware relays NFC card data for fraudulent payments

Malware Activity
H score30 First: 07.01.2026 18:00 Last: 07.01.2026 18:00 Sources 1

About this happening: A wave of Android tap-to-pay malware is enabling unauthorized contactless payments by relaying NFC card data from victims’ phones to criminal devices. The operation us...

Wonderland Android SMS stealer activity targeting Uzbekistan

Malware Activity
H score27 First: 22.12.2025 08:11 Last: 22.12.2025 08:11 Sources 1

About this happening: The Wonderland Android SMS stealer is being spread through malicious droppers in attacks targeting users in Uzbekistan, enabling SMS and OTP theft and bank-card fr...

Timeline

  1. 12.08.2026 17:30 2 articles · 1h ago

    Group-IB documents WindRelay and SpyNote live-call NFC relay fraud

    Initial Disclosure

    Group-IB described WindRelay, a previously unseen NFC relay malware family used with a SpyNote RAT in a 13-minute live-call scam, where a fraudster posed as a bank employee, used remote access to install WindRelay, captured the chip-and-reader exchange when the victim tapped a card, relayed the data to a fake terminal, and used the same access to take out a loan in the victim's banking app. Group-IB also linked WindRelay to 23 VirusTotal samples uploaded between November 2025 and July 2026 that impersonated institutions in Czechia, Slovakia and Slovenia.

    Show sources