HomeRisk ManagementsWindRelay Malware Combines with SpyNote RAT in Live-Call Scam

WindRelay Malware Combines with SpyNote RAT in Live-Call Scam

Published on

spot_img

NFC Relay Malware Family Uncovered in High-Stakes Fraud Scheme

In a striking display of cybercriminal ingenuity, a previously unseen family of NFC relay malware has been identified, accompanied by a remote access trojan (RAT) during a single, remarkably short phone call that lasted only 13 minutes. This malicious pairing enabled a fraudster not only to take out a loan in the name of the unsuspecting victim but also to capture their card data, relaying it to a bogus terminal while deftly keeping the victim engaged on the line.

This sophisticated incident was meticulously documented by Group-IB, a cybersecurity firm known for its investigative prowess, in a technical write-up released on August 12. The newly identified NFC malware has been named "WindRelay," while the RAT has been attributed to a variant of the notorious SpyNote malware, traditionally targeted at Android devices. The case provides a disturbing glimpse into modern fraud tactics, highlighting how criminals can leverage technology to manipulate victims while maintaining the façade of legitimacy.

The Fraudster’s Artful Deception

The perpetrator of this fraud executed the scheme by impersonating a bank employee and presenting the ruse as a necessary troubleshooting step regarding the victim’s credit card. After establishing trust through this impersonation, the fraudster walked the victim through the installation process of an app that would prove instrumental in the cyber heist. This tactic of utilizing social engineering to manipulate victims into compliance showcases the layered complexities of modern-day scams.

As the victim proceeded with the installation, they remained unaware that they were being led down a path that would result in significant financial harm. The RAT leveraged a standard device package installer for sideloading the application—a technique that circumvents official app stores but is widely recognized in the cybersecurity community. Intriguingly, the application was uniquely labeled with the victim’s name rather than opting for a generic or fraudulent brand, a troubling indication of how fraudsters conduct pre-call reconnaissance to personalize their attacks. By using the victim’s name, the app created a false sense of security, leading the victim to proceed without hesitation.

Methodical Execution of the Fraud

Once the RAT was successfully installed, the fraudster used it to install WindRelay, eliminating the need for any further intervention from the victim. This method of operation stands out because it involved no screen-sharing whatsoever, allowing the fraudster to maintain a low profile while executing their plan.

The permissions granted to WindRelay painted a stark picture of the malware’s capabilities. It was able to utilize NFC technology to read card information, leverage an internet connection to stream captured data in real-time, access the victim’s contacts for potential further targets, and execute a device state inspection via an unusual "DUMP" command, typically not found in third-party applications. These features enabled the malware to act as a contactless reader, capturing real-time transactions, including one-time codes generated during exchanges.

When the victim tapped their card as instructed, the malware activated, facilitating the interception of communication between the card and the terminal. Crucially, this captured data was then transmitted live to a second device controlled by the fraudster, who presented the card information to a legitimate payment terminal, effectively masquerading as the real cardholder.

Opportunistic Loan Application

In a further escalation of their criminal scheme, the fraudster exploited the ongoing access to the victim’s banking app to apply for a loan. Group-IB noted that this action seemed more opportunistic rather than a premeditated element of the fraud. The rapid emergence of unauthorized card transactions followed closely after the call concluded, indicating that the criminal had capitalized on their access without delay.

Upon investigation, Group-IB found a concerning connection between WindRelay and 23 malware samples uploaded to VirusTotal between November 2025 and July 2026. These samples appeared to target institutions across Czechia, Slovakia, and Slovenia, emphasizing the cross-border implications of such cyber threats.

Preventive Measures and Recommendations

In light of these findings, Group-IB has issued several recommendations aimed at mitigating future risks associated with such scams. They advise against relying solely on screen-sharing detection as an assurance of having remote access; instead, firms should maintain vigilance over app installations from unofficial sources during active calls. Additionally, they recommend monitoring for loan disbursements that coincide with real-time card transactions, which can serve as a red flag for fraudulent activity.

The emergence of the WindRelay malware in conjunction with a remote access trojan illustrates the evolving landscape of cybercrime, where fraudsters are becoming increasingly sophisticated in their methods. As technology continues to advance, so too must the strategies employed by victims and institutions to safeguard against these cunning attacks.

Source link

Latest articles

Cyber Briefing – 2026.08.12 – CyberMaterial

Cyber Briefing: Key Developments in Cybersecurity In the ever-evolving world of cybersecurity, significant advancements and...

Prioritizing Identity Risk Management

SailPoint • July 3, 2026 ...

Security Theatre: Active Metrics in the SOC Create an Impressive Display but Fail in Defense

Rethinking Security Metrics: Why Risk Reduction Should Take Center Stage The landscape of cybersecurity is...

Email and Messaging Security Tailored for You Webinar

ISMG Welcomes New Registrants: Key Steps for Completing Your Profile The Information Security Media Group...

More like this

Cyber Briefing – 2026.08.12 – CyberMaterial

Cyber Briefing: Key Developments in Cybersecurity In the ever-evolving world of cybersecurity, significant advancements and...

Prioritizing Identity Risk Management

SailPoint • July 3, 2026 ...

Security Theatre: Active Metrics in the SOC Create an Impressive Display but Fail in Defense

Rethinking Security Metrics: Why Risk Reduction Should Take Center Stage The landscape of cybersecurity is...