WindRelay NFC relay malware deployed with SpyNote RAT
Malware Activity
Summary
Hide ▲
Show ▼
WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and relayed it in real time to a fraudster’s device. Group-IB said it was first detected in the wild in late August 2025, and the activity expanded beyond the Czech Republic to Brazil, Poland, and Slovakia over the past year. The same chain also used SpyNote for remote access, including to silently sideload and activate the NFC app and to abuse the victim’s banking app. Group-IB linked the malware to 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026.
Related Happenings
WindRelay Android NFC relay malware activity
Malware Activity
H score20
First: 20.08.2026 15:01
Last: 20.08.2026 15:01
Sources 1
About this happening:
Group-IB identified WindRelay, a previously unseen Android NFC relay malware family used with SpyNote RAT in live-call social engineering against victims in ...
WindRelay Android NFC relay malware activity
Malware ActivityAbout this happening: Group-IB identified WindRelay, a previously unseen Android NFC relay malware family used with SpyNote RAT in live-call social engineering against victims in ...
GoldFactory GoldDigger Android banking campaign targeting South Africa and the U.K.
Campaign
H score41
First: 20.08.2026 13:38
Last: 20.08.2026 13:38
Sources 1
About this happening:
A GoldDigger Android banking campaign is driving mass infections in South Africa and the U.K., using fake airline and shopping apps to steal credentials and trigge...
GoldFactory GoldDigger Android banking campaign targeting South Africa and the U.K.
CampaignAbout this happening: A GoldDigger Android banking campaign is driving mass infections in South Africa and the U.K., using fake airline and shopping apps to steal credentials and trigge...
Manic Android malware activity with offline relay exfiltration
Malware Activity
H score29
First: 20.08.2026 13:02
Last: 20.08.2026 13:02
Sources 1
About this happening:
Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
Manic Android malware activity with offline relay exfiltration
Malware ActivityAbout this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
WindRelay and SpyNote RAT Android NFC relay fraud activity
Malware Activity
H score33
First: 13.08.2026 01:22
Last: 13.08.2026 01:22
Sources 1
About this happening:
The WindRelay and SpyNote RAT malware chain is stealing payment card data from Android devices and enabling fraudulent transactions in real time. The activity uses...
WindRelay and SpyNote RAT Android NFC relay fraud activity
Malware ActivityAbout this happening: The WindRelay and SpyNote RAT malware chain is stealing payment card data from Android devices and enabling fraudulent transactions in real time. The activity uses...
Timeline
-
12.08.2026 17:30 3 articles · 13d ago
Group-IB documents WindRelay and SpyNote live-call NFC relay fraud
Initial DisclosureGroup-IB described WindRelay, a previously unseen NFC relay malware family used with a SpyNote RAT in a 13-minute live-call scam, where a fraudster posed as a bank employee, used remote access to install WindRelay, captured the chip-and-reader exchange when the victim tapped a card, relayed the data to a fake terminal, and used the same access to take out a loan in the victim's banking app. Group-IB also linked WindRelay to 23 VirusTotal samples uploaded between November 2025 and July 2026 that impersonated institutions in Czechia, Slovakia and Slovenia.
Show sources
- WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam — www.infosecurity-magazine.com — 12.08.2026 17:30
- WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam — www.infosecurity-magazine.com — 12.08.2026 17:30
- WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud — thehackernews.com — 13.08.2026 14:53