logo

WindRelay Turns Android Phones Into Fake Payment Terminals for Remote Card Fraud

ID: 00ac37ad-4a16-5d5c-8c3f-f9ed735e0e5b

STIX ID: report--00ac37ad-4a16-5d5c-8c3f-f9ed735e0e5b

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-08-12

Date Updated: 2026-08-12

Author: Mayura Kathir

...
...

Group-IB describes WindRelay, a newly identified Android malware family used alongside a SpyNote RAT to convert victims' phones into live NFC relay devices during social-engineered vishing calls, enabling real-time card-present fraud ('ghost tap'); the report covers the attack chain (sideloaded, personalized SpyNote abusing Accessibility to install WindRelay), technical capabilities (NFC relay, internet relaying, device-inspection permissions), observed samples and C2 IPs across several European countries, IOCs, and recommended detection/mitigation guidance for banks and defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.