Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme

b7620d95bed4cff8ab8dc779f2295badb8009a2b5aa59cee7f971c1abc33d16b

TLP:CLEAR
Active

SHA-256 Hash

Description

A new NFC relay malware family called WindRelay has been discovered operating in combination with SpyNote RAT to enable sophisticated contactless payment fraud. The scheme uses live social engineering phone calls where fraudsters impersonate bank employees and guide victims to install personalized RAT malware labeled with the victim's own name. Once installed, the RAT enables silent deployment of WindRelay, which captures contactless payment card data via NFC when victims tap their cards to their phones. The captured data is relayed in real-time to fraudster-controlled terminals for immediate cash-out through physical purchases or ATM withdrawals. The operation employs dual monetization, combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 WindRelay samples targeting victims in Czechia, Slovakia, and Slovenia between November 2025 and July 2026.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
Pattern Type
STIX
Confidence
75%
Valid From
Aug 12, 2026 18:01
Total Sightings
0
Added
Aug 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of b7620d95bed4cff8ab8dc779f2295badb8009a2b5aa59cee7f971c1abc33d16b

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.