Skip to main content

Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme

0
Medium
Published: 08/12/2026 (08/12/2026, 12:12:48 UTC)
Source: AlienVault OTX General

Description

A new NFC relay malware family called WindRelay has been discovered operating in combination with SpyNote RAT to enable sophisticated contactless payment fraud. The scheme uses live social engineering phone calls where fraudsters impersonate bank employees and guide victims to install personalized RAT malware labeled with the victim's own name. Once installed, the RAT enables silent deployment of WindRelay, which captures contactless payment card data via NFC when victims tap their cards to their phones. The captured data is relayed in real-time to fraudster-controlled terminals for immediate cash-out through physical purchases or ATM withdrawals. The operation employs dual monetization, combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 WindRelay samples targeting victims in Czechia, Slovakia, and Slovenia between November 2025 and July 2026.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 17:29:59 UTC

Technical Analysis

WindRelay is an NFC relay malware family discovered working alongside SpyNote RAT to enable contactless payment fraud. Attackers conduct live social engineering calls impersonating bank employees to convince victims to install a RAT malware personalized with their own names. This RAT then silently installs WindRelay, which captures NFC payment card data when victims tap their cards to their phones. The captured data is relayed in real-time to attacker-controlled terminals, enabling immediate cash-out through physical purchases or ATM withdrawals. The operation uses dual monetization by combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 samples targeting victims in Czechia, Slovakia, and Slovenia from November 2025 to July 2026.

Potential Impact

The malware enables attackers to steal contactless payment card data in real-time and perform immediate fraudulent transactions such as physical purchases and ATM withdrawals. Additionally, the SpyNote RAT facilitates digital loan fraud, increasing the financial impact on victims. The combined use of RAT and NFC relay malware increases the sophistication and potential financial loss from this fraud scheme.

Defensive Guidance

No official patch or remediation is available as this is a malware campaign relying on social engineering and user interaction. Defenders should focus on user education to recognize social engineering attempts, avoid installing untrusted applications, and monitor for suspicious RAT activity on devices. Financial institutions should be aware of this fraud vector and consider additional verification steps for contactless transactions and digital loan applications. Since this is not a software vulnerability, no direct patch exists.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/"]
Pulse Id
6a7c6340682f0dc9b225d8d6

Indicators of Compromise

Ip

ValueDescriptionCopy
ip185.100.87.116
—
ip185.100.87.223
—
ip213.218.160.48
—

Hash

ValueDescriptionCopy
hash12ce0d5bcd316a2aaa3f789f4e7de022
—
hash1414b2b93358ccc04878f920f59242d4
—
hash16573b21ac4e52882fe7a2c9713d19d9
—
hash1ca333874544155d462c90d4b3882ffd
—
hash25b1a83140cc18a9d537d1c2c3a1221f
—
hash2c0e1a5efaa707656380fca445a166d5
—
hash2e93f4fd7b2fdc177dd2bba248ec1ad3
—
hash33b64d40ac1a5ffefb1f22dd75d12184
—
hash54a8fc9f54db580c4c0599ea5ec3a675
—
hash550eeef212d9bdd103b24b517311f603
—
hash555936f73595c30677b062a5abfe1aad
—
hash629bdda67ae3f42101f77cdafb4a44cb
—
hash6ae642656e38a7f62a60ca32afd86254
—
hash7e6f38fc19fbcc7d86058c84e2468551
—
hash82325d35c55cdb836cbb04ccadd4238d
—
hash84cee9591649a267adf4b178a8f45774
—
hash91eb55f8b5210247cdc55ed6ae1dac6a
—
hash9f4b9b4832d6ff1c5fb1e84ecddf68a4
—
hasha0571f2ae3dd6dba972ac8cd26786336
—
hashc63a6e9930f831c004eed9780376117b
—
hashcfe835e8a9132ef190c7eedf2cfaa9e9
—
hash11f9fb29f2cc142e81c804f53599ae36282c95b3
—
hash1371b2b2da10ed178d26a7aad191634553f865ae
—
hash193078cda795dc2f12983e9b66821f7e67c6495d
—
hash1eac0c636edf181eec0315ffe3b5b1e310b1a352
—
hash217ab41d543278d0ecce797a71ef38a6bc1493fe
—
hash22fa5c967b0775c3f3398dcf5dbb46ff80e1708b
—
hash294ecf0550308dff9df0eea86ca127c064b3bfb8
—
hash38ca1bc31ccdc1c650720abd76bcc619532c0166
—
hash39060c673aefa0902cb5fc787fa53364cad9ed6f
—
hash48d011117eacf57128c7e473bb5d4d69e3d41ef6
—
hash50cf07b97ef999e9fc5c7efae19d0e5f39db39fa
—
hash56b819cb285dbdbc307268b4fadbddaa61319bb8
—
hash65ca7e9363539282c2670dfab100b75c9bfb6253
—
hash67e2a1e8ab963086bb768b28307cf58dadb0acc7
—
hash6feeba25748996d3928f11ef774122e02b4b8850
—
hash82a35dd0ec20791bc3161a87fdb6caa68fd3d4a6
—
hash850680506df7892d43b3382f0f89a06ef18837c7
—
hash852322e063872a025b711d5adf08531eac36a265
—
hash8e665c12b7d8e80c72d86ed4425663ecd74e453c
—
hash91e66d640b2a570bd83b408b51ebbf21e95e7469
—
hasha1574476a616599a202cc731a6d5dbf9b3a635f0
—
hasha72089566a711ed0781d5a36e3c289de0de13e2d
—
hashbc2bce53d71533c2eb1ccc30ef252ea2774d0100
—
hashbce3d9b06a3fc2312fe5be213f3d98b9350c9b22
—
hashdfd19ee8b550f21b99d63ce87d039d1e8e1e111b
—
hashe05575afe5a01d150daa8b4bb935213cc0e538f6
—
hashe2e836d16a1b50d4d091f7ae507b82c0a8e05376
—
hashea2be784b2c08cd6f116e14079d6583ba606c556
—
hashec730da64f9feae4259ebc88113c5cebdf2b1ad7
—
hash17f8231dcfdeee8ff3aa14b97375ba6a55e1fee500833e2d6191713a2ddc0a90
—
hash1c2da449573b8355c68d7fb16b6fda3c010ba224952374bd02b6d8e0a3b5a03b
—
hash22f01c554cdbb22afe10a12c55a446efc5fed2a4309196a4a298147b6655b121
—
hash25d096b74ab643ed1669c5d942f93677d7fdfdd30def6e0dfac4f8062b4a0af0
—
hash3b98169f7d9f8a25f466c64a63074f5c09901ad568be89b8dba28018898a0f8b
—
hash3f0eea6c320e0d5c1ad83a00c02d3ac20dc4ef9e6204d7866211cb315436e0b2
—
hash43410e4d540d83fb46a9e745950217073464fa79b74601b8542fa98127c5f36f
—
hash4b51b11b4f3548f5c69ceacbe6e8ea89dfea0ee74ae373e5f02616b53caaf9cf
—
hash53831b969f257da4fd13966fbebbd793e052e71b901a748405f7560ba1c117ff
—
hash5a0c716f0264ece8fa7a90b498886cb34eb8785da34724d4001c2b67abacb4e1
—
hash60294bf6be02361fa989de9d504f1e11563a34d45db5be5b74868e80fdb2a41f
—
hash653201819cb651d397c8c01f36036cd317e53dd1eb61a337051f246a3008a11f
—
hash66e4174630c8ff3d2f7236b6b3bb3201a82655cc6a9d39702b8ab243cabea2dc
—
hash6aefddd5825d27b2f5c3c3ef339d0731fda0757f50fd843d9909728622f174ec
—
hash85c1e56dcd1f6228915262b55ac29c9d5ec83542b0e7ac66fedee6be5f689be1
—
hashab91a5d6365a21b89a0cee76148abb4fe98b05b4a0c8cea99f3934a12b9bd432
—
hashb7620d95bed4cff8ab8dc779f2295badb8009a2b5aa59cee7f971c1abc33d16b
—
hashbd50868665605df7332702b7d70942cf63f273a88c99c4a7384deb72d31611aa
—
hashe5701b3ec6b8d1132295098f1544a5ac98617eb9d188db7f625627cb57c1895d
—
hashe9f0a03dff09df07f830877ad49109ed47bbaaea184c4c9f046202d73f0932e1
—
hashee91767b80e5b1545777672f3596d6960281bdc3f27abe66c563370ab6dc9125
—

Threat ID: 6a7c942abf8831d539c065c8

Added to database: 08/12/2026, 15:41:30 UTC

Last enriched: 08/12/2026, 17:29:59 UTC

Last updated: 09/24/2026, 23:40:40 UTC

Views: 116

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses