Find notable cyber news and cases, enriched with sources, timelines, and signals.

WindRelay and SpyNote RAT Android NFC relay fraud activity

Malware Activity
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

The WindRelay and SpyNote RAT malware chain is stealing payment card data from Android devices and enabling fraudulent transactions in real time. The activity uses a bank-impersonation call, a sideloaded fake app, and Accessibility Service abuse to gain device control before the attacker installs WindRelay and relays NFC card data. Samples seen between November 2025 and July 2026 indicate a sustained malware set, and targeting appears focused on Czechia, Slovakia, and Slovenia.

Related Happenings

WindRelay NFC relay malware deployed with SpyNote RAT

Malware Activity
H score19 First: 12.08.2026 17:30 Last: 12.08.2026 17:30 Sources 1

About this happening: The WindRelay malware chain turned a 13-minute phone call into live card fraud, relaying a victim’s card data to a fake terminal and helping an operator take out a loa...

RedWing Android spyware rented through Telegram

Malware Activity
H score21 First: 08.07.2026 18:30 Last: 08.07.2026 18:30 Sources 1

About this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...

RedWing Android bank-fraud malware rental service

Malware Activity
H score21 First: 07.07.2026 20:10 Last: 07.07.2026 20:10 Sources 1

About this happening: The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...

Rokarolla Android banking trojan activity

Malware Activity
H score26 First: 16.06.2026 16:15 Last: 16.06.2026 16:15 Sources 1

About this happening: The Rokarolla Android banking trojan is expanding phone-level control on infected devices, letting attackers steal credentials, intercept authentication codes, and hide fr...

NFCShare Android malware spreads via fake banking-app updates

Malware Activity
H score21 First: 09.06.2026 01:11 Last: 09.06.2026 01:11 Sources 1

About this happening: The NFCShare Android malware is being spread as fake banking-app updates on GitHub, broadening attacks against customers of multiple banks and financial institutions acr...

Timeline

  1. 13.08.2026 01:22 2 articles · 2h ago

    Android fraud chain relays NFC card data with WindRelay and SpyNote

    Initial Disclosure

    A bank-impersonation phone call pushed an Android victim to sideload a fake SpyNote RAT app and grant Accessibility Service permissions, giving remote access that was used to install WindRelay, relay live NFC payment-card data to an attacker-controlled device, and carry out fraudulent purchases and a loan in the victim’s name.

    Show sources