WindRelay Malware Uses SpyNote RAT, NFC Relay to Drain Accounts
Key Takeaways A new Android fraud campaign, dubbed “WindRelay,” is leveraging a combination of SpyNote Remote Access Trojan (RAT) and novel NFC relay malware. The attack begins with a...
Key Takeaways
- A new Android fraud campaign, dubbed “WindRelay,” is leveraging a combination of SpyNote Remote Access Trojan (RAT) and novel NFC relay malware.
- The attack begins with a sophisticated social engineering phone call, impersonating a bank employee, to trick victims into installing malicious applications.
- Within minutes, attackers can gain full control over a victim’s banking app, initiate fraudulent loans, and conduct physical, contactless payments using the victim’s own card data via NFC relay.
- The scheme has been observed targeting individuals in Czechia, Slovakia, and Slovenia.
- Vigilance against unsolicited calls and never installing apps from unverified sources are crucial mitigation steps.
A sophisticated new Android fraud operation is rapidly transforming convincing social engineering phone calls into significant financial losses for victims. This campaign, tracked as “WindRelay,” employs a potent combination of the well-known SpyNote remote-control tool and a newly identified family of NFC relay malware. Together, these tools grant cybercriminals extensive access to a victim’s banking applications and enable fraudulent physical payment card transactions in a remarkably short timeframe.
Table Of Content
The Anatomy of a 13-Minute Financial Heist
The attack chain is initiated by a caller who impersonates a bank representative, alleging an issue with the customer’s payment card. Through this deceptive tactic, the victim is persuaded to install a malicious application while remaining on the phone call, allowing the fraudster to establish control over their device. In one documented instance, a loan was fraudulently issued, and card data was relayed for illicit purchases, all within a mere 13 minutes.
Security researchers at Group-IB said in a report that their fraud-protection team uncovered this malware pairing during an incident investigation. The case highlights a particularly insidious form of contactless payment abuse: rather than simply stealing and storing card details, the attacker’s phone acts as an intermediary, bridging the legitimate card with a criminal’s device to facilitate real-time transactions.
The repercussions of such an attack extend beyond a single unauthorized transaction. Malicious actors can manipulate settings within a victim’s banking application, while the NFC component enables “card-present” payments that appear legitimate to merchant terminals, making detection even more challenging for financial institutions. Group-IB emphasized that victims often remain unaware they are being defrauded, believing they are following bank instructions until the funds have already been siphoned off. This rapid execution leaves minimal time for banks or customers to identify suspicious activity, dispute payments, or prevent a full account takeover.
SpyNote and WindRelay: A Potent Malware Duo
The initial phase of the attack involves the caller convincing the victim to sideload a SpyNote-based application from an unofficial source. To enhance its credibility, the app’s label was customized to include the victim’s actual name. Previous instances of SpyNote fake Play Store pages demonstrate how deceptive delivery mechanisms can grant criminals extensive control over Android devices.
SpyNote exploits Android’s Accessibility Service, enabling the attacker to install and activate the second malicious application, WindRelay, without requiring screen sharing. This means the victim might not visually perceive the attacker’s actions, making the compromise harder to detect. The fraudster then proceeds to use the victim’s banking application to secure a loan in their name. The absence of a visible screen-sharing session should not be misconstrued as an indicator of device safety.
WindRelay is subsequently installed via the package installer. The criminal instructs the victim to tap their payment card against their phone and input their PIN. The malware intercepts and relays this live NFC exchange between the card and the phone’s reader over the internet in real time. Crucially, this data is not a static, reusable card number but a live communication stream. Because the data is relayed instantaneously, standard payment checks often perceive a valid chip conversation, making it exceptionally difficult to distinguish from a legitimate tap transaction.
A second attacker-controlled device then presents this relayed exchange to an actual payment terminal, effectively acting as an invisible conduit in the transaction. The bank later confirmed NFC relay activity after fraudulent physical card charges appeared. This method echoes previous Android malware cash withdrawals, which enable ATM withdrawals or purchases without the criminal physically possessing the original card.
This dual-pronged attack strategy creates two distinct avenues for financial gain: digital lending through remote banking access and card-present fraud via NFC relaying. Researchers have identified WindRelay campaigns actively targeting individuals in Czechia, Slovakia, and Slovenia.
What You Should Do
For Individuals:
- Be Skeptical of Unsolicited Calls: Any unexpected call from someone claiming to be from your bank, especially if they ask you to install an app, enable accessibility features, tap your card, or reveal your PIN, is a major red flag.
- Verify Independently: If you receive such a call, hang up immediately. Contact your bank directly using a trusted phone number (from their official website or the back of your card), not a number provided by the caller.
- Never Install Apps from Unknown Sources: Only download applications from official app stores (Google Play Store) and verify the developer. Be extremely cautious of sideloading apps.
- Review Account Activity: Regularly check your bank statements and transaction history for any unauthorized activity.
- Preserve Evidence: If you suspect you’ve been targeted, note the exact name of any installed applications and report it to your bank and relevant authorities immediately.
For Financial Institutions and Organizations:
- Monitor for Unusual App Installations: Implement systems to detect applications installed from unofficial sources, particularly if they request high-risk permissions like accessibility, NFC, internet access, or device administration.
- Flag Personalized App Labels: Be alert to app labels that incorporate customer-specific information, as this indicates a targeted social engineering effort.
- Correlate Suspicious Activities: Look for concurrent suspicious events, such as a loan request immediately followed by physical card transactions, which can indicate a coordinated fraud attack.
- Enhance Authentication: For high-risk transactions like loan requests, implement stronger authentication methods or introduce out-of-band confirmation processes and delays.
- Advanced Threat Detection: Move beyond signature-based detection and focus on behavioral analysis to identify unusual permission combinations and rapid sequences of actions indicative of malware-driven fraud.
- Incident Response: When an NFC relay incident is reported, thoroughly investigate all related account channels (e.g., new payees, transfers, lending activity) to assess the full scope of compromise.
This campaign underscores a broader trend towards sophisticated contactless fraud, where social engineering is combined with innovative technology to bypass traditional security measures. The most effective defense for consumers remains simple: never install software or tap a card at the behest of an unsolicited caller.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| C2 IP | 88[.]86[.]124[.]114 | WindRelay C2 infrastructure |
| C2 IP | 185[.]100[.]87[.]116 | WindRelay C2 infrastructure |
| C2 IP | 185[.]100[.]87[.]223 | WindRelay C2 infrastructure |
| C2 IP | 213[.]218[.]160[.]48 | WindRelay C2 infrastructure |
| SHA-1 | 852322e063872a025b711d5adf08531eac36a265 | WindRelay malware sample |
| SHA-1 | 11f9fb29f2cc142e81c804f53599ae36282c95b3 | WindRelay malware sample |
| SHA-1 | 50cf07b97ef999e9fc5c7efae19d0e5f39db39fa | WindRelay malware sample |
| SHA-1 | 850680506df7892d43b3382f0f89a06ef18837c7 | WindRelay malware sample |
| SHA-1 | 1371b2b2da10ed178d26a7aad191634553f865ae | WindRelay malware sample |
| SHA-1 | 91e66d640b2a570bd83b408b51ebbf21e95e7469 | WindRelay malware sample |
| SHA-1 | 39060c673aefa0902cb5fc787fa53364cad9ed6f | WindRelay malware sample |
| SHA-1 | e2e836d16a1b50d4d091f7ae507b82c0a8e05376 | WindRelay malware sample |
| SHA-1 | 56b819cb285dbdbc307268b4fadbddaa61319bb8 | WindRelay malware sample |
| SHA-1 | a1574476a616599a202cc731a6d5dbf9b3a635f0 | WindRelay malware sample |
| SHA-1 | 48d011117eacf57128c7e473bb5d4d69e3d41ef6 | WindRelay malware sample |
| SHA-1 | ec7
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.