WindRelay Android NFC relay malware activity
Malware Activity
Summary
Hide ▲
Show ▼
Group-IB identified WindRelay, a previously unseen Android NFC relay malware family used with SpyNote RAT in live-call social engineering against victims in Czechia, Slovakia, and Slovenia. The activity matters because the malware relays active card traffic in real time, supporting payment abuse without altering the card's expiration data. Evidence links the operation to 23 samples and four C2 IP addresses.
Related Happenings
WindRelay and SpyNote RAT Android NFC relay fraud activity
Malware Activity
H score33
First: 13.08.2026 01:22
Last: 13.08.2026 01:22
Sources 1
About this happening:
The WindRelay and SpyNote RAT malware chain is stealing payment card data from Android devices and enabling fraudulent transactions in real time. The activity uses...
WindRelay and SpyNote RAT Android NFC relay fraud activity
Malware ActivityAbout this happening: The WindRelay and SpyNote RAT malware chain is stealing payment card data from Android devices and enabling fraudulent transactions in real time. The activity uses...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware Activity
H score20
First: 12.08.2026 17:30
Last: 12.08.2026 17:30
Sources 1
About this happening:
WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware ActivityAbout this happening: WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
Android tap-to-pay malware relays NFC card data for fraudulent payments
Malware Activity
H score30
First: 07.01.2026 18:00
Last: 07.01.2026 18:00
Sources 1
About this happening:
A wave of Android tap-to-pay malware is enabling unauthorized contactless payments by relaying NFC card data from victims’ phones to criminal devices. The operation us...
Android tap-to-pay malware relays NFC card data for fraudulent payments
Malware ActivityAbout this happening: A wave of Android tap-to-pay malware is enabling unauthorized contactless payments by relaying NFC card data from victims’ phones to criminal devices. The operation us...
Timeline
-
12.08.2026 03:00 2 articles · 8d ago
Group-IB documents WindRelay Android NFC relay malware
Initial DisclosureGroup-IB documented WindRelay, a previously unseen Android NFC relay malware family, and described its deployment alongside the SpyNote remote access trojan in live-call social engineering against victims in Czechia, Slovakia, and Slovenia. The activity used a two-device relay primitive to relay an active card in real time without touching the expiration date, and Group-IB identified 23 samples uploaded to VirusTotal between November 2025 and July 2026 plus four command-and-control IP addresses.
Show sources
- Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments — thehackernews.com — 20.08.2026 15:01
- Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments — thehackernews.com — 20.08.2026 15:01