WindRelay and SpyNote RAT Android NFC relay fraud activity
Malware Activity
Summary
Hide ▲
Show ▼
The WindRelay and SpyNote RAT malware chain is stealing payment card data from Android devices and enabling fraudulent transactions in real time. The activity uses a bank-impersonation call, a sideloaded fake app, and Accessibility Service abuse to gain device control before the attacker installs WindRelay and relays NFC card data. Samples seen between November 2025 and July 2026 indicate a sustained malware set, and targeting appears focused on Czechia, Slovakia, and Slovenia.
Related Happenings
WindRelay Android NFC relay malware activity
Malware Activity
H score20
First: 20.08.2026 15:01
Last: 20.08.2026 15:01
Sources 1
About this happening:
Group-IB identified WindRelay, a previously unseen Android NFC relay malware family used with SpyNote RAT in live-call social engineering against victims in ...
WindRelay Android NFC relay malware activity
Malware ActivityAbout this happening: Group-IB identified WindRelay, a previously unseen Android NFC relay malware family used with SpyNote RAT in live-call social engineering against victims in ...
GoldFactory GoldDigger Android banking campaign targeting South Africa and the U.K.
Campaign
H score41
First: 20.08.2026 13:38
Last: 20.08.2026 13:38
Sources 1
About this happening:
A GoldDigger Android banking campaign is driving mass infections in South Africa and the U.K., using fake airline and shopping apps to steal credentials and trigge...
GoldFactory GoldDigger Android banking campaign targeting South Africa and the U.K.
CampaignAbout this happening: A GoldDigger Android banking campaign is driving mass infections in South Africa and the U.K., using fake airline and shopping apps to steal credentials and trigge...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware Activity
H score20
First: 12.08.2026 17:30
Last: 12.08.2026 17:30
Sources 1
About this happening:
WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware ActivityAbout this happening: WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
RedWing Android spyware rented through Telegram
Malware Activity
H score21
First: 08.07.2026 18:30
Last: 08.07.2026 18:30
Sources 1
About this happening:
The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android spyware rented through Telegram
Malware ActivityAbout this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android bank-fraud malware rental service
Malware Activity
H score21
First: 07.07.2026 20:10
Last: 07.07.2026 20:10
Sources 1
About this happening:
The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...
RedWing Android bank-fraud malware rental service
Malware ActivityAbout this happening: The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...
Timeline
-
13.08.2026 01:22 2 articles · 13d ago
Android fraud chain relays NFC card data with WindRelay and SpyNote
Initial DisclosureA bank-impersonation phone call pushed an Android victim to sideload a fake SpyNote RAT app and grant Accessibility Service permissions, giving remote access that was used to install WindRelay, relay live NFC payment-card data to an attacker-controlled device, and carry out fraudulent purchases and a loan in the victim’s name.
Show sources
- Android malware combo takes out loans and relays victims' credit cards — www.bleepingcomputer.com — 13.08.2026 01:22
- Android malware combo takes out loans and relays victims' credit cards — www.bleepingcomputer.com — 13.08.2026 01:22