Tektronix TIF 2026
This page was machine-translated and may differ from the original. View original

Group-IB Discovers NFC Relay Malware 'WindRelay'

Google 우선 소스Published2026.09.02 09:23

Simultaneously Stealing Loan and Card Information During 13-Minute Call via SpyNote RAT Integration

 
A new malware strain exploiting NFC functionality to transmit victims' contactless card data in real-time to fake payment terminals has been detected. When combined with a remote access trojan (RAT), it performs simultaneous digital and physical financial theft within a single call session, classifying it as a new threat type distinct from existing NFC relay attacks.
 
Group-IB announced on the 2nd that it has confirmed an undisclosed NFC relay malware family designated as 'WindRelay'.


According to an actual attack case documented by Group-IB's fraud prevention team, fraudsters induced victims to install SpyNote RAT during phone calls impersonating bank employees.

After obtaining remote access privileges, they covertly installed WindRelay on the victim's device, then simultaneously proceeded with a loan application in the victim's name and real-time relay of card NFC data within the same 13-minute call.

When the victim tapped their card once and entered their PIN, the stolen data was transmitted to a remote fake terminal, resulting in cash withdrawals.

As a result of Group-IB researchers' analysis of WindRelay's permissions, it was confirmed that the malware includes △NFC card data capture △internet access for real-time data exfiltration △contact access for acquiring additional targets △system inspection △customized permissions for evading security tool detection.

The analysis indicates it is an intentionally designed attack toolkit.

Group-IB traced the campaign's origin to Central and Eastern Europe.

Between November 2025 and July 2026, associations were confirmed between 23 malicious samples uploaded to VirusTotal and 4 command-and-control (C&C) servers in Czechia, Slovakia, and Slovenia.

According to independent telemetry data, NFC-based attacks targeting Android devices increased 188% year-over-year from January to April 2026.
 
Group-IB urged financial institutions and mobile banking providers in the South Korean market, which has high contactless and mobile payment adoption rates, to prepare for the same attack patterns.

Specifically, it stated recommendations include △strengthening monitoring of RAT indicators such as sideloaded apps and accessibility service exploitation installed during calls, rather than relying solely on screen sharing detection △setting external app installations outside official app markets as independent risk signals △implementing correlation analysis between loan disbursements and concurrent card face-to-face transactions.
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.
명세환 기자
명세환 Reporter