Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastruc

August 12, 2026

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

August 12, 2026

WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam

August 12, 2026
Facebook X (Twitter) Instagram
Wednesday, August 12
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam
Cyber Security

WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam

Team-CWDBy Team-CWDAugust 12, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A previously unseen NFC relay malware family has been deployed alongside a remote access trojan in a single 13-minute phone call, letting a fraudster take out a loan in the victim’s name and relay their card data to a fake terminal while keeping them on the line.

Group-IB documented the case in a technical write-up published on August 12, tracking the NFC malware as WindRelay and attributing the remote access trojan (RAT) to a variant of SpyNote.

The fraudster called posing as a bank employee reporting a problem with the victim’s card, then talked them through installing the first app.

Read more on NFC relay fraud: Ghost Tap Malware Fuels Surge in Remote NFC Payment Fraud

An App Named After Its Victim

The RAT arrived through the device’s package installer, the standard route for sideloading outside an app store. Its app label carried the victim’s own name, rather than a generic or impersonated brand.

SpyNote ships with a builder toolkit letting an operator set a custom app name, label and package name, so personalization is built in rather than manual effort.

Group-IB said the label pointed to pre-call reconnaissance harvesting the victim’s name and phone number, and meant there was no unfamiliar app name to give the victim pause.

With the RAT active, the fraudster used its remote access to install WindRelay himself, requiring nothing further from the victim. No screen sharing was triggered at any point.

One Tap, Two Payouts

WindRelay’s permissions mapped its purpose: NFC to read the card, INTERNET to stream captures out live, READ_CONTACTS to reach further targets and DUMP, unusual in a third-party app, to inspect device state.

When the victim tapped their card as instructed, the malware acted as a contactless reader, capturing the live exchange between chip and reader including the one-time code generated for that transaction. That exchange was streamed to a second device held by the fraudster, which presented itself as the card to a real terminal.

The fraudster used the same access to take out a loan through the victim’s banking app, which Group-IB read as an opportunistic add-on rather than a planned step. Card transactions began appearing shortly after the call ended.

Group-IB linked WindRelay to 23 samples uploaded to VirusTotal between November 2025 and July 2026, impersonating institutions in Czechia, Slovakia and Slovenia.

Its recommendations to avoid the scam include not treating screen-sharing detection as a proxy for remote access, alerting on app installations from non-official sources during an active call and flagging loan disbursements that coincide with physical card transactions.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleLazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Next Article TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Team-CWD
  • Website

Related Posts

Cyber Security

Cursor Security Bug Allowed Repositories to Execute Commands Pre Trust

August 11, 2026
Cyber Security

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

August 10, 2026
Cyber Security

Addressing Vulnerability Management Together in the Age of AI

August 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

Is it time for internet services to adopt identity verification?

January 14, 2026

How to mitigate the security and privacy risks of smart glasses

May 11, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.