TECH Signal 439
WindRelay campaign relays live NFC card data through victim's Android phone within 13 minutes
Group-IB discovered a fraud campaign called WindRelay that combines social engineering phone calls, SpyNote RAT, and NFC relay malware to capture live EMV transaction data from Android users and authorize fraudulent payments before banks can intervene.
This attack turns the victim's own device into a relay for genuine card-present transactions, making the fraud nearly indistinguishable from legitimate activity because the real card chip completes an authentic handshake with the terminal. The 13-minute window from initial call to cash-out leaves almost no time for automated fraud detection or customer intervention.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Attackers pose as bank helpdesk staff and guide victims to install SpyNote RAT, which silently drops WindRelay NFC relay malware during the same call.
WindRelay captures live EMV APDU exchange data when victims tap their card and enter their PIN, and the attacker relays this to a second device for fraudulent purchases or ATM withdrawals.
Group-IB observed 23 WindRelay samples on VirusTotal between November 2025 and July 2026 targeting victims in Czechia, Slovakia, and Slovenia, with personalized builds suggesting pre-attack reconnaissance.
THE CLUSTER