Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme

0
Medium
Published: 08/12/2026 (08/12/2026, 12:12:48 UTC)
Source: AlienVault OTX General

Description

WindRelay is a newly identified malware family that operates in conjunction with the SpyNote RAT to facilitate sophisticated contactless payment fraud. Fraudsters use social engineering via live phone calls to trick victims into installing a personalized RAT labeled with the victim's name. This RAT silently deploys WindRelay, which captures NFC contactless payment card data when victims tap their cards to their phones. The stolen data is relayed in real-time to fraudster-controlled terminals for immediate fraudulent transactions, including physical purchases and ATM withdrawals. The scheme combines digital loan fraud via the RAT with NFC-based card-present fraud. Group-IB reported 23 WindRelay samples targeting victims in Czechia, Slovakia, and Slovenia between November 2025 and July 2026.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 17:29:59 UTC

Technical Analysis

WindRelay is an NFC relay malware family discovered working alongside SpyNote RAT to enable contactless payment fraud. Attackers conduct live social engineering calls impersonating bank employees to convince victims to install a RAT malware personalized with their own names. This RAT then silently installs WindRelay, which captures NFC payment card data when victims tap their cards to their phones. The captured data is relayed in real-time to attacker-controlled terminals, enabling immediate cash-out through physical purchases or ATM withdrawals. The operation uses dual monetization by combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 samples targeting victims in Czechia, Slovakia, and Slovenia from November 2025 to July 2026.

Potential Impact

The malware enables attackers to steal contactless payment card data in real-time and perform immediate fraudulent transactions such as physical purchases and ATM withdrawals. Additionally, the SpyNote RAT facilitates digital loan fraud, increasing the financial impact on victims. The combined use of RAT and NFC relay malware increases the sophistication and potential financial loss from this fraud scheme.

Defensive Guidance

No official patch or remediation is available as this is a malware campaign relying on social engineering and user interaction. Defenders should focus on user education to recognize social engineering attempts, avoid installing untrusted applications, and monitor for suspicious RAT activity on devices. Financial institutions should be aware of this fraud vector and consider additional verification steps for contactless transactions and digital loan applications. Since this is not a software vulnerability, no direct patch exists.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/"]
Adversary
null
Pulse Id
6a7c6340682f0dc9b225d8d6
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip185.100.87.116
ip185.100.87.223
ip213.218.160.48

Hash

ValueDescriptionCopy
hash12ce0d5bcd316a2aaa3f789f4e7de022
hash1414b2b93358ccc04878f920f59242d4
hash16573b21ac4e52882fe7a2c9713d19d9
hash1ca333874544155d462c90d4b3882ffd
hash25b1a83140cc18a9d537d1c2c3a1221f
hash2c0e1a5efaa707656380fca445a166d5
hash2e93f4fd7b2fdc177dd2bba248ec1ad3
hash33b64d40ac1a5ffefb1f22dd75d12184
hash54a8fc9f54db580c4c0599ea5ec3a675
hash550eeef212d9bdd103b24b517311f603
hash555936f73595c30677b062a5abfe1aad
hash629bdda67ae3f42101f77cdafb4a44cb
hash6ae642656e38a7f62a60ca32afd86254
hash7e6f38fc19fbcc7d86058c84e2468551
hash82325d35c55cdb836cbb04ccadd4238d
hash84cee9591649a267adf4b178a8f45774
hash91eb55f8b5210247cdc55ed6ae1dac6a
hash9f4b9b4832d6ff1c5fb1e84ecddf68a4
hasha0571f2ae3dd6dba972ac8cd26786336
hashc63a6e9930f831c004eed9780376117b
hashcfe835e8a9132ef190c7eedf2cfaa9e9
hash11f9fb29f2cc142e81c804f53599ae36282c95b3
hash1371b2b2da10ed178d26a7aad191634553f865ae
hash193078cda795dc2f12983e9b66821f7e67c6495d
hash1eac0c636edf181eec0315ffe3b5b1e310b1a352
hash217ab41d543278d0ecce797a71ef38a6bc1493fe
hash22fa5c967b0775c3f3398dcf5dbb46ff80e1708b
hash294ecf0550308dff9df0eea86ca127c064b3bfb8
hash38ca1bc31ccdc1c650720abd76bcc619532c0166
hash39060c673aefa0902cb5fc787fa53364cad9ed6f
hash48d011117eacf57128c7e473bb5d4d69e3d41ef6
hash50cf07b97ef999e9fc5c7efae19d0e5f39db39fa
hash56b819cb285dbdbc307268b4fadbddaa61319bb8
hash65ca7e9363539282c2670dfab100b75c9bfb6253
hash67e2a1e8ab963086bb768b28307cf58dadb0acc7
hash6feeba25748996d3928f11ef774122e02b4b8850
hash82a35dd0ec20791bc3161a87fdb6caa68fd3d4a6
hash850680506df7892d43b3382f0f89a06ef18837c7
hash852322e063872a025b711d5adf08531eac36a265
hash8e665c12b7d8e80c72d86ed4425663ecd74e453c
hash91e66d640b2a570bd83b408b51ebbf21e95e7469
hasha1574476a616599a202cc731a6d5dbf9b3a635f0
hasha72089566a711ed0781d5a36e3c289de0de13e2d
hashbc2bce53d71533c2eb1ccc30ef252ea2774d0100
hashbce3d9b06a3fc2312fe5be213f3d98b9350c9b22
hashdfd19ee8b550f21b99d63ce87d039d1e8e1e111b
hashe05575afe5a01d150daa8b4bb935213cc0e538f6
hashe2e836d16a1b50d4d091f7ae507b82c0a8e05376
hashea2be784b2c08cd6f116e14079d6583ba606c556
hashec730da64f9feae4259ebc88113c5cebdf2b1ad7
hash17f8231dcfdeee8ff3aa14b97375ba6a55e1fee500833e2d6191713a2ddc0a90
hash1c2da449573b8355c68d7fb16b6fda3c010ba224952374bd02b6d8e0a3b5a03b
hash22f01c554cdbb22afe10a12c55a446efc5fed2a4309196a4a298147b6655b121
hash25d096b74ab643ed1669c5d942f93677d7fdfdd30def6e0dfac4f8062b4a0af0
hash3b98169f7d9f8a25f466c64a63074f5c09901ad568be89b8dba28018898a0f8b
hash3f0eea6c320e0d5c1ad83a00c02d3ac20dc4ef9e6204d7866211cb315436e0b2
hash43410e4d540d83fb46a9e745950217073464fa79b74601b8542fa98127c5f36f
hash4b51b11b4f3548f5c69ceacbe6e8ea89dfea0ee74ae373e5f02616b53caaf9cf
hash53831b969f257da4fd13966fbebbd793e052e71b901a748405f7560ba1c117ff
hash5a0c716f0264ece8fa7a90b498886cb34eb8785da34724d4001c2b67abacb4e1
hash60294bf6be02361fa989de9d504f1e11563a34d45db5be5b74868e80fdb2a41f
hash653201819cb651d397c8c01f36036cd317e53dd1eb61a337051f246a3008a11f
hash66e4174630c8ff3d2f7236b6b3bb3201a82655cc6a9d39702b8ab243cabea2dc
hash6aefddd5825d27b2f5c3c3ef339d0731fda0757f50fd843d9909728622f174ec
hash85c1e56dcd1f6228915262b55ac29c9d5ec83542b0e7ac66fedee6be5f689be1
hashab91a5d6365a21b89a0cee76148abb4fe98b05b4a0c8cea99f3934a12b9bd432
hashb7620d95bed4cff8ab8dc779f2295badb8009a2b5aa59cee7f971c1abc33d16b
hashbd50868665605df7332702b7d70942cf63f273a88c99c4a7384deb72d31611aa
hashe5701b3ec6b8d1132295098f1544a5ac98617eb9d188db7f625627cb57c1895d
hashe9f0a03dff09df07f830877ad49109ed47bbaaea184c4c9f046202d73f0932e1
hashee91767b80e5b1545777672f3596d6960281bdc3f27abe66c563370ab6dc9125

Threat ID: 6a7c942abf8831d539c065c8

Added to database: 08/12/2026, 15:41:30 UTC

Last enriched: 08/12/2026, 17:29:59 UTC

Last updated: 08/12/2026, 20:16:15 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses