Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
WindRelay is a newly identified malware family that operates in conjunction with the SpyNote RAT to facilitate sophisticated contactless payment fraud. Fraudsters use social engineering via live phone calls to trick victims into installing a personalized RAT labeled with the victim's name. This RAT silently deploys WindRelay, which captures NFC contactless payment card data when victims tap their cards to their phones. The stolen data is relayed in real-time to fraudster-controlled terminals for immediate fraudulent transactions, including physical purchases and ATM withdrawals. The scheme combines digital loan fraud via the RAT with NFC-based card-present fraud. Group-IB reported 23 WindRelay samples targeting victims in Czechia, Slovakia, and Slovenia between November 2025 and July 2026.
AI Analysis
Technical Summary
WindRelay is an NFC relay malware family discovered working alongside SpyNote RAT to enable contactless payment fraud. Attackers conduct live social engineering calls impersonating bank employees to convince victims to install a RAT malware personalized with their own names. This RAT then silently installs WindRelay, which captures NFC payment card data when victims tap their cards to their phones. The captured data is relayed in real-time to attacker-controlled terminals, enabling immediate cash-out through physical purchases or ATM withdrawals. The operation uses dual monetization by combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 samples targeting victims in Czechia, Slovakia, and Slovenia from November 2025 to July 2026.
Potential Impact
The malware enables attackers to steal contactless payment card data in real-time and perform immediate fraudulent transactions such as physical purchases and ATM withdrawals. Additionally, the SpyNote RAT facilitates digital loan fraud, increasing the financial impact on victims. The combined use of RAT and NFC relay malware increases the sophistication and potential financial loss from this fraud scheme.
Mitigation Recommendations
No official patch or remediation is available as this is a malware campaign relying on social engineering and user interaction. Defenders should focus on user education to recognize social engineering attempts, avoid installing untrusted applications, and monitor for suspicious RAT activity on devices. Financial institutions should be aware of this fraud vector and consider additional verification steps for contactless transactions and digital loan applications. Since this is not a software vulnerability, no direct patch exists.
Affected Countries
Czechia, Slovakia, Slovenia
Indicators of Compromise
- ip: 185.100.87.116
- hash: 12ce0d5bcd316a2aaa3f789f4e7de022
- hash: 1414b2b93358ccc04878f920f59242d4
- hash: 16573b21ac4e52882fe7a2c9713d19d9
- hash: 1ca333874544155d462c90d4b3882ffd
- hash: 25b1a83140cc18a9d537d1c2c3a1221f
- hash: 2c0e1a5efaa707656380fca445a166d5
- hash: 2e93f4fd7b2fdc177dd2bba248ec1ad3
- hash: 33b64d40ac1a5ffefb1f22dd75d12184
- hash: 54a8fc9f54db580c4c0599ea5ec3a675
- hash: 550eeef212d9bdd103b24b517311f603
- hash: 555936f73595c30677b062a5abfe1aad
- hash: 629bdda67ae3f42101f77cdafb4a44cb
- hash: 6ae642656e38a7f62a60ca32afd86254
- hash: 7e6f38fc19fbcc7d86058c84e2468551
- hash: 82325d35c55cdb836cbb04ccadd4238d
- hash: 84cee9591649a267adf4b178a8f45774
- hash: 91eb55f8b5210247cdc55ed6ae1dac6a
- hash: 9f4b9b4832d6ff1c5fb1e84ecddf68a4
- hash: a0571f2ae3dd6dba972ac8cd26786336
- hash: c63a6e9930f831c004eed9780376117b
- hash: cfe835e8a9132ef190c7eedf2cfaa9e9
- hash: 11f9fb29f2cc142e81c804f53599ae36282c95b3
- hash: 1371b2b2da10ed178d26a7aad191634553f865ae
- hash: 193078cda795dc2f12983e9b66821f7e67c6495d
- hash: 1eac0c636edf181eec0315ffe3b5b1e310b1a352
- hash: 217ab41d543278d0ecce797a71ef38a6bc1493fe
- hash: 22fa5c967b0775c3f3398dcf5dbb46ff80e1708b
- hash: 294ecf0550308dff9df0eea86ca127c064b3bfb8
- hash: 38ca1bc31ccdc1c650720abd76bcc619532c0166
- hash: 39060c673aefa0902cb5fc787fa53364cad9ed6f
- hash: 48d011117eacf57128c7e473bb5d4d69e3d41ef6
- hash: 50cf07b97ef999e9fc5c7efae19d0e5f39db39fa
- hash: 56b819cb285dbdbc307268b4fadbddaa61319bb8
- hash: 65ca7e9363539282c2670dfab100b75c9bfb6253
- hash: 67e2a1e8ab963086bb768b28307cf58dadb0acc7
- hash: 6feeba25748996d3928f11ef774122e02b4b8850
- hash: 82a35dd0ec20791bc3161a87fdb6caa68fd3d4a6
- hash: 850680506df7892d43b3382f0f89a06ef18837c7
- hash: 852322e063872a025b711d5adf08531eac36a265
- hash: 8e665c12b7d8e80c72d86ed4425663ecd74e453c
- hash: 91e66d640b2a570bd83b408b51ebbf21e95e7469
- hash: a1574476a616599a202cc731a6d5dbf9b3a635f0
- hash: a72089566a711ed0781d5a36e3c289de0de13e2d
- hash: bc2bce53d71533c2eb1ccc30ef252ea2774d0100
- hash: bce3d9b06a3fc2312fe5be213f3d98b9350c9b22
- hash: dfd19ee8b550f21b99d63ce87d039d1e8e1e111b
- hash: e05575afe5a01d150daa8b4bb935213cc0e538f6
- hash: e2e836d16a1b50d4d091f7ae507b82c0a8e05376
- hash: ea2be784b2c08cd6f116e14079d6583ba606c556
- hash: ec730da64f9feae4259ebc88113c5cebdf2b1ad7
- hash: 17f8231dcfdeee8ff3aa14b97375ba6a55e1fee500833e2d6191713a2ddc0a90
- hash: 1c2da449573b8355c68d7fb16b6fda3c010ba224952374bd02b6d8e0a3b5a03b
- hash: 22f01c554cdbb22afe10a12c55a446efc5fed2a4309196a4a298147b6655b121
- hash: 25d096b74ab643ed1669c5d942f93677d7fdfdd30def6e0dfac4f8062b4a0af0
- hash: 3b98169f7d9f8a25f466c64a63074f5c09901ad568be89b8dba28018898a0f8b
- hash: 3f0eea6c320e0d5c1ad83a00c02d3ac20dc4ef9e6204d7866211cb315436e0b2
- hash: 43410e4d540d83fb46a9e745950217073464fa79b74601b8542fa98127c5f36f
- hash: 4b51b11b4f3548f5c69ceacbe6e8ea89dfea0ee74ae373e5f02616b53caaf9cf
- hash: 53831b969f257da4fd13966fbebbd793e052e71b901a748405f7560ba1c117ff
- hash: 5a0c716f0264ece8fa7a90b498886cb34eb8785da34724d4001c2b67abacb4e1
- hash: 60294bf6be02361fa989de9d504f1e11563a34d45db5be5b74868e80fdb2a41f
- hash: 653201819cb651d397c8c01f36036cd317e53dd1eb61a337051f246a3008a11f
- hash: 66e4174630c8ff3d2f7236b6b3bb3201a82655cc6a9d39702b8ab243cabea2dc
- hash: 6aefddd5825d27b2f5c3c3ef339d0731fda0757f50fd843d9909728622f174ec
- hash: 85c1e56dcd1f6228915262b55ac29c9d5ec83542b0e7ac66fedee6be5f689be1
- hash: ab91a5d6365a21b89a0cee76148abb4fe98b05b4a0c8cea99f3934a12b9bd432
- hash: b7620d95bed4cff8ab8dc779f2295badb8009a2b5aa59cee7f971c1abc33d16b
- hash: bd50868665605df7332702b7d70942cf63f273a88c99c4a7384deb72d31611aa
- hash: e5701b3ec6b8d1132295098f1544a5ac98617eb9d188db7f625627cb57c1895d
- hash: e9f0a03dff09df07f830877ad49109ed47bbaaea184c4c9f046202d73f0932e1
- hash: ee91767b80e5b1545777672f3596d6960281bdc3f27abe66c563370ab6dc9125
- ip: 185.100.87.223
- ip: 213.218.160.48
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
Description
WindRelay is a newly identified malware family that operates in conjunction with the SpyNote RAT to facilitate sophisticated contactless payment fraud. Fraudsters use social engineering via live phone calls to trick victims into installing a personalized RAT labeled with the victim's name. This RAT silently deploys WindRelay, which captures NFC contactless payment card data when victims tap their cards to their phones. The stolen data is relayed in real-time to fraudster-controlled terminals for immediate fraudulent transactions, including physical purchases and ATM withdrawals. The scheme combines digital loan fraud via the RAT with NFC-based card-present fraud. Group-IB reported 23 WindRelay samples targeting victims in Czechia, Slovakia, and Slovenia between November 2025 and July 2026.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
WindRelay is an NFC relay malware family discovered working alongside SpyNote RAT to enable contactless payment fraud. Attackers conduct live social engineering calls impersonating bank employees to convince victims to install a RAT malware personalized with their own names. This RAT then silently installs WindRelay, which captures NFC payment card data when victims tap their cards to their phones. The captured data is relayed in real-time to attacker-controlled terminals, enabling immediate cash-out through physical purchases or ATM withdrawals. The operation uses dual monetization by combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 samples targeting victims in Czechia, Slovakia, and Slovenia from November 2025 to July 2026.
Potential Impact
The malware enables attackers to steal contactless payment card data in real-time and perform immediate fraudulent transactions such as physical purchases and ATM withdrawals. Additionally, the SpyNote RAT facilitates digital loan fraud, increasing the financial impact on victims. The combined use of RAT and NFC relay malware increases the sophistication and potential financial loss from this fraud scheme.
Defensive Guidance
No official patch or remediation is available as this is a malware campaign relying on social engineering and user interaction. Defenders should focus on user education to recognize social engineering attempts, avoid installing untrusted applications, and monitor for suspicious RAT activity on devices. Financial institutions should be aware of this fraud vector and consider additional verification steps for contactless transactions and digital loan applications. Since this is not a software vulnerability, no direct patch exists.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/"]
- Adversary
- null
- Pulse Id
- 6a7c6340682f0dc9b225d8d6
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip185.100.87.116 | — | |
ip185.100.87.223 | — | |
ip213.218.160.48 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash12ce0d5bcd316a2aaa3f789f4e7de022 | — | |
hash1414b2b93358ccc04878f920f59242d4 | — | |
hash16573b21ac4e52882fe7a2c9713d19d9 | — | |
hash1ca333874544155d462c90d4b3882ffd | — | |
hash25b1a83140cc18a9d537d1c2c3a1221f | — | |
hash2c0e1a5efaa707656380fca445a166d5 | — | |
hash2e93f4fd7b2fdc177dd2bba248ec1ad3 | — | |
hash33b64d40ac1a5ffefb1f22dd75d12184 | — | |
hash54a8fc9f54db580c4c0599ea5ec3a675 | — | |
hash550eeef212d9bdd103b24b517311f603 | — | |
hash555936f73595c30677b062a5abfe1aad | — | |
hash629bdda67ae3f42101f77cdafb4a44cb | — | |
hash6ae642656e38a7f62a60ca32afd86254 | — | |
hash7e6f38fc19fbcc7d86058c84e2468551 | — | |
hash82325d35c55cdb836cbb04ccadd4238d | — | |
hash84cee9591649a267adf4b178a8f45774 | — | |
hash91eb55f8b5210247cdc55ed6ae1dac6a | — | |
hash9f4b9b4832d6ff1c5fb1e84ecddf68a4 | — | |
hasha0571f2ae3dd6dba972ac8cd26786336 | — | |
hashc63a6e9930f831c004eed9780376117b | — | |
hashcfe835e8a9132ef190c7eedf2cfaa9e9 | — | |
hash11f9fb29f2cc142e81c804f53599ae36282c95b3 | — | |
hash1371b2b2da10ed178d26a7aad191634553f865ae | — | |
hash193078cda795dc2f12983e9b66821f7e67c6495d | — | |
hash1eac0c636edf181eec0315ffe3b5b1e310b1a352 | — | |
hash217ab41d543278d0ecce797a71ef38a6bc1493fe | — | |
hash22fa5c967b0775c3f3398dcf5dbb46ff80e1708b | — | |
hash294ecf0550308dff9df0eea86ca127c064b3bfb8 | — | |
hash38ca1bc31ccdc1c650720abd76bcc619532c0166 | — | |
hash39060c673aefa0902cb5fc787fa53364cad9ed6f | — | |
hash48d011117eacf57128c7e473bb5d4d69e3d41ef6 | — | |
hash50cf07b97ef999e9fc5c7efae19d0e5f39db39fa | — | |
hash56b819cb285dbdbc307268b4fadbddaa61319bb8 | — | |
hash65ca7e9363539282c2670dfab100b75c9bfb6253 | — | |
hash67e2a1e8ab963086bb768b28307cf58dadb0acc7 | — | |
hash6feeba25748996d3928f11ef774122e02b4b8850 | — | |
hash82a35dd0ec20791bc3161a87fdb6caa68fd3d4a6 | — | |
hash850680506df7892d43b3382f0f89a06ef18837c7 | — | |
hash852322e063872a025b711d5adf08531eac36a265 | — | |
hash8e665c12b7d8e80c72d86ed4425663ecd74e453c | — | |
hash91e66d640b2a570bd83b408b51ebbf21e95e7469 | — | |
hasha1574476a616599a202cc731a6d5dbf9b3a635f0 | — | |
hasha72089566a711ed0781d5a36e3c289de0de13e2d | — | |
hashbc2bce53d71533c2eb1ccc30ef252ea2774d0100 | — | |
hashbce3d9b06a3fc2312fe5be213f3d98b9350c9b22 | — | |
hashdfd19ee8b550f21b99d63ce87d039d1e8e1e111b | — | |
hashe05575afe5a01d150daa8b4bb935213cc0e538f6 | — | |
hashe2e836d16a1b50d4d091f7ae507b82c0a8e05376 | — | |
hashea2be784b2c08cd6f116e14079d6583ba606c556 | — | |
hashec730da64f9feae4259ebc88113c5cebdf2b1ad7 | — | |
hash17f8231dcfdeee8ff3aa14b97375ba6a55e1fee500833e2d6191713a2ddc0a90 | — | |
hash1c2da449573b8355c68d7fb16b6fda3c010ba224952374bd02b6d8e0a3b5a03b | — | |
hash22f01c554cdbb22afe10a12c55a446efc5fed2a4309196a4a298147b6655b121 | — | |
hash25d096b74ab643ed1669c5d942f93677d7fdfdd30def6e0dfac4f8062b4a0af0 | — | |
hash3b98169f7d9f8a25f466c64a63074f5c09901ad568be89b8dba28018898a0f8b | — | |
hash3f0eea6c320e0d5c1ad83a00c02d3ac20dc4ef9e6204d7866211cb315436e0b2 | — | |
hash43410e4d540d83fb46a9e745950217073464fa79b74601b8542fa98127c5f36f | — | |
hash4b51b11b4f3548f5c69ceacbe6e8ea89dfea0ee74ae373e5f02616b53caaf9cf | — | |
hash53831b969f257da4fd13966fbebbd793e052e71b901a748405f7560ba1c117ff | — | |
hash5a0c716f0264ece8fa7a90b498886cb34eb8785da34724d4001c2b67abacb4e1 | — | |
hash60294bf6be02361fa989de9d504f1e11563a34d45db5be5b74868e80fdb2a41f | — | |
hash653201819cb651d397c8c01f36036cd317e53dd1eb61a337051f246a3008a11f | — | |
hash66e4174630c8ff3d2f7236b6b3bb3201a82655cc6a9d39702b8ab243cabea2dc | — | |
hash6aefddd5825d27b2f5c3c3ef339d0731fda0757f50fd843d9909728622f174ec | — | |
hash85c1e56dcd1f6228915262b55ac29c9d5ec83542b0e7ac66fedee6be5f689be1 | — | |
hashab91a5d6365a21b89a0cee76148abb4fe98b05b4a0c8cea99f3934a12b9bd432 | — | |
hashb7620d95bed4cff8ab8dc779f2295badb8009a2b5aa59cee7f971c1abc33d16b | — | |
hashbd50868665605df7332702b7d70942cf63f273a88c99c4a7384deb72d31611aa | — | |
hashe5701b3ec6b8d1132295098f1544a5ac98617eb9d188db7f625627cb57c1895d | — | |
hashe9f0a03dff09df07f830877ad49109ed47bbaaea184c4c9f046202d73f0932e1 | — | |
hashee91767b80e5b1545777672f3596d6960281bdc3f27abe66c563370ab6dc9125 | — |
Threat ID: 6a7c942abf8831d539c065c8
Added to database: 08/12/2026, 15:41:30 UTC
Last enriched: 08/12/2026, 17:29:59 UTC
Last updated: 08/12/2026, 20:16:15 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.