WindRelay NFC Relay Malware combined with SpyNote RAT
First seen Aug 13, 2026 · Updated Aug 13, 2026
A newly identified Android malware campaign pairs a novel NFC relay tool called WindRelay with the established SpyNote RAT to capture and relay victims' live credit card data to attackers in real time. The combo also facilitates taking out fraudulent loans using stolen victim information, indicating a financially motivated criminal operation targeting mobile banking users.
Technical Analysis
WindRelay abuses Android's NFC host-card emulation capabilities to intercept and relay contactless payment card data from a victim's device to an attacker-controlled device, enabling near-instant fraudulent point-of-sale or ATM transactions. SpyNote, a long-standing commodity Android RAT, provides the initial foothold via sideloaded APKs or phishing lures, granting attackers remote control, SMS interception (useful for OTP/2FA bypass), and device surveillance capabilities. The combined toolset suggests a modular attack chain: SpyNote establishes persistence and credential/OTP theft, while WindRelay handles real-time card-present fraud relay, and stolen identity/financial data is further leveraged to apply for loans in victims' names. No CVEs are associated with this threat, as it relies on social engineering, sideloading, and abuse of legitimate NFC APIs rather than exploiting a software vulnerability. There is no direct evidence of impact to AI agent systems, as this campaign targets consumer mobile banking users rather than agent infrastructure or credential stores used by LLM/agent frameworks.
Affected Systems
Android devices (versions supporting NFC host-card emulation and sideloaded APK installation), particularly those with mobile banking and contactless payment apps installed
Indicators of Compromise
- SpyNote RAT APK samples (hashes not provided in source)
- WindRelay malicious APK packages (hashes not provided in source)
- Sideloaded APK distribution links/domains (not specified in source)
Remediation Steps
- 1
Disable sideloading
Ensure 'Install unknown apps' is disabled on Android devices and only install apps from Google Play or verified enterprise stores.
- 2
Enable Google Play Protect
Verify Play Protect is active and regularly scanning installed applications for known malware signatures.
- 3
Restrict NFC usage
Disable NFC when not actively performing contactless payments to reduce relay attack windows.
- 4
Monitor for anomalous transactions
Financial institutions should implement real-time fraud detection for rapid, geographically inconsistent contactless transactions.
- 5
User awareness training
Educate users on risks of installing APKs from unofficial sources, phishing links, and fake banking/utility apps.
- 6
Mobile threat defense (MTD)
Deploy enterprise MTD solutions to detect RAT behavior such as SpyNote's command-and-control communications and screen/SMS access.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.