logo

WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam

ID: 5b33ff03-6fe5-57e5-97c9-5c4bef48d859

STIX ID: report--5b33ff03-6fe5-57e5-97c9-5c4bef48d859

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-08-12

Date Updated: 2026-08-12

...
...

A social-engineering campaign delivered a SpyNote-based RAT via sideloading during a phone call, then the attacker used remote access to install a new NFC relay malware called WindRelay that acted as a contactless reader to stream live chip-to-terminal exchanges (including one-time transaction codes) to a fraudster’s device; the attacker also used access to take out loans in victims’ banking apps. Group-IB documented 23 WindRelay samples on VirusTotal (Nov 2025–Jul 2026) and recommended detecting non-store app installs during calls, not relying solely on screen-sharing alerts, and flagging loan disbursements coincident with card transactions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.