13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A new Android fraud operation shows how quickly a convincing phone call can turn into financial loss.

The campaign combines the SpyNote remote-control tool with WindRelay, a newly tracked NFC relay malware family. Together, they give criminals access to a victim’s banking app and physical payment card in one short session.

The attack starts with a caller posing as a bank employee and claiming there is a problem with the customer’s card.

The victim is persuaded to install an app and remains on the call while the criminal takes control.

In the investigated case, a loan was issued and card data relayed for fraudulent purchases within 13 minutes.

Analysts at Group-IB identified the malware pairing during an investigation supported by its fraud-protection team.

The case highlights contactless-payment abuse in which a phone bridges a genuine card and a criminal’s device, rather than simply storing stolen card details.

The damage goes beyond one unauthorized transaction. Attackers can change settings inside a banking app, while the NFC component supports card-present payments that may appear legitimate to a merchant terminal.

Attack chain (Source – Group-IB)

Group-IB said in a report shared with Cyber Security News (CSN) that Victims may believe they are following bank instructions until the cash-out is already under way.

That speed leaves little time for a bank or customer to recognize suspicious activity, challenge a payment, and stop the account takeover.

13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware

The caller convinced the victim to sideload a SpyNote-based app outside the official app store. Its label used the victim’s own name, a detail designed to make it look familiar.

Similar SpyNote fake Play pages show how deceptive delivery can give criminals extensive Android control.

SpyNote abused Android’s Accessibility Service, allowing the operator to install and activate the second application without screen sharing.

The fraudster then used the banking application to obtain a loan in the victim’s name. The lack of a visible screen-sharing session should not be treated as proof that a device is safe.

WindRelay was installed shortly afterward through the package installer. The criminal instructed the victim to tap a payment card against the phone and enter the PIN.

SpyNote APK Builder allows for data customization (Source – Group-IB)

The malware read the live NFC exchange between card and reader and sent it across the internet in real time, not as a reusable card number.

Since the data is relayed live, ordinary payment checks can see a valid chip conversation, making the event harder to distinguish from a normal tap.

A second attacker-controlled device presented that exchange to a real payment terminal, acting as an invisible link in the transaction. The bank later confirmed NFC relay activity after physical card charges appeared.

Earlier Android malware cash withdrawals show the same risk: relay tools can enable ATM withdrawals or purchases without the criminal holding the original card.

This pairing created two payout paths: digital lending through remote banking access and card-present fraud through NFC relaying. Researchers tracked WindRelay in campaigns targeting Czechia, Slovakia, and Slovenia.

How users and banks can respond

The clearest warning sign is an unexpected support call asking someone to install an application, enable accessibility access, tap a card, or reveal a PIN.

A legitimate bank should be contacted independently through a trusted number or official app. Hanging up and verifying the request can interrupt the criminal’s control before second-stage malware is added.

Organizations should watch for apps installed from non-official sources during active calls, especially when they request accessibility, NFC, internet, or device-administration permissions.

They should also investigate personalized app labels and closely timed loan requests and physical card transactions. These clues expose social engineering followed by fast, automated actions.

Defenders should not rely only on known file signatures. Group-IB recommends detecting unusual permission combinations and using out-of-band confirmation, delays, or stronger authentication for risky loan requests.

Monitoring a reported NFC relay incident for new payees, transfers, and lending activity can reveal damage across multiple account channels.

Customers who suspect this scam should immediately contact their bank using a verified route, explain that apps were installed during a call, and review recent account activity.

They should also preserve the exact application name for investigators. This campaign reflects a wider shift toward contactless fraud.

Reports on Ghost Tap payment fraud and new NFC relay malware show criminals pairing a convincing pretext with technology that relays a live card conversation.

For consumers, the safest response is simple: never install software or tap a card because an unsolicited caller tells you to do so.

Indicators of compromise (IoCs):-

Type Indicator Description
C2 IP 88[.]86[.]124[.]114 WindRelay C2 infrastructure
C2 IP 185[.]100[.]87[.]116 WindRelay C2 infrastructure
C2 IP 185[.]100[.]87[.]223 WindRelay C2 infrastructure
C2 IP 213[.]218[.]160[.]48 WindRelay C2 infrastructure
SHA-1 852322e063872a025b711d5adf08531eac36a265 WindRelay malware sample
SHA-1 11f9fb29f2cc142e81c804f53599ae36282c95b3 WindRelay malware sample
SHA-1 50cf07b97ef999e9fc5c7efae19d0e5f39db39fa WindRelay malware sample
SHA-1 850680506df7892d43b3382f0f89a06ef18837c7 WindRelay malware sample
SHA-1 1371b2b2da10ed178d26a7aad191634553f865ae WindRelay malware sample
SHA-1 91e66d640b2a570bd83b408b51ebbf21e95e7469 WindRelay malware sample
SHA-1 39060c673aefa0902cb5fc787fa53364cad9ed6f WindRelay malware sample
SHA-1 e2e836d16a1b50d4d091f7ae507b82c0a8e05376 WindRelay malware sample
SHA-1 56b819cb285dbdbc307268b4fadbddaa61319bb8 WindRelay malware sample
SHA-1 a1574476a616599a202cc731a6d5dbf9b3a635f0 WindRelay malware sample
SHA-1 48d011117eacf57128c7e473bb5d4d69e3d41ef6 WindRelay malware sample
SHA-1 ec730da64f9feae4259ebc88113c5cebdf2b1ad7 WindRelay malware sample
SHA-1 8e665c12b7d8e80c72d86ed4425663ecd74e453c WindRelay malware sample
SHA-1 67e2a1e8ab963086bb768b28307cf58dadb0acc7 WindRelay malware sample
SHA-1 294ecf0550308dff9df0eea86ca127c064b3bfb8 WindRelay malware sample
SHA-1 65ca7e9363539282c2670dfab100b75c9bfb6253 WindRelay malware sample
SHA-1 dfd19ee8b550f21b99d63ce87d039d1e8e1e111b WindRelay malware sample
SHA-1 217ab41d543278d0ecce797a71ef38a6bc1493fe WindRelay malware sample
SHA-1 82a35dd0ec20791bc3161a87fdb6caa68fd3d4a6 WindRelay malware sample
SHA-1 6feeba25748996d3928f11ef774122e02b4b8850 WindRelay malware sample
SHA-1 1eac0c636edf181eec0315ffe3b5b1e310b1a352 WindRelay malware sample
SHA-1 ea2be784b2c08cd6f116e14079d6583ba606c556 WindRelay malware sample
SHA-1 e05575afe5a01d150daa8b4bb935213cc0e538f6 SpyNote RAT malware sample
SHA-1 193078cda795dc2f12983e9b66821f7e67c6495d SpyNote RAT malware sample
SHA-1 38ca1bc31ccdc1c650720abd76bcc619532c0166 SpyNote RAT malware sample
SHA-1 22fa5c967b0775c3f3398dcf5dbb46ff80e1708b SpyNote RAT malware sample
SHA-1 bce3d9b06a3fc2312fe5be213f3d98b9350c9b22 SpyNote RAT malware sample
SHA-1 bc2bce53d71533c2eb1ccc30ef252ea2774d0100 SpyNote RAT malware sample
SHA-1 a72089566a711ed0781d5a36e3c289de0de13e2d SpyNote RAT malware sample

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world