WindRelay and SpyNote Malware Enable NFC Relay Fraud Scheme

WindRelay and SpyNote Malware Enable NFC Relay Fraud Scheme

First seen 12 Aug 2026, 13:08 UTC Group-Ibwww.eset.comCybersecuritynewsgbhackers.com 86% similarity 66.5

Article Content

Browse articles
ThreatCluster

A new malware combination, WindRelay and SpyNote RAT, has emerged, facilitating NFC relay fraud through social engineering. This attack allows criminals to access victims' banking apps and payment cards in a single session. The European Payments Council reported a significant rise in NFC relay fraud, with a 188% increase in attacks on Android devices in early 2026 compared to the previous year. Law enforcement has noted the spread of these attacks, particularly in Central and Eastern Europe, with over 35,600 attacks blocked in the first four months of 2026. The malware exploits vulnerabilities in contactless payment systems, leading to unauthorized transactions and potential money laundering. The first documented attacks began in late 2023 in the Czech Republic, with subsequent arrests. The scale of the fraud is underscored by the identification of over 70 command-and-control servers linked to these campaigns.

Key Points: • WindRelay malware combined with SpyNote RAT enables NFC relay fraud. • NFC relay attacks on Android devices surged by 188% in early 2026. • Over 35,600 NFC-based attacks were blocked in the first four months of 2026.

ThreatCluster AI How this analysis works

Timeline

2023-12-01
First documented WindRelay attacks
Initial attacks using modified NFCGate tool reported in the Czech Republic.
Group-IB
2024-03-15
Czech Police arrest suspect
A 22-year-old was arrested for suspicious ATM withdrawals without a card.
Group-IB
2026-04-30
Surge in NFC relay attacks
Blocked NFC-based attacks on Android devices reached 35,600, a 188% increase from 2025.
Group-IB
2026-08-12
New malware combination reported
WindRelay and SpyNote RAT identified as tools in a growing fraud scheme.
Cybersecuritynews

Community

Browse all →