← Blog · · df00tech

WindRelay NFC Relay Malware Paired with SpyNote RAT to Drain Android Users' Cards in Real Time

security-news campaign

What happened

According to BleepingComputer, researchers have identified a new Android NFC relay malware dubbed WindRelay being deployed alongside the SpyNote remote administration tool (RAT). The combination allows attackers to capture live payment card data from infected devices and relay it to attackers in real time, reportedly enabling fraudulent loan applications and unauthorized card transactions. Full technical details of the infection chain and distribution method were not covered in the available summary.

Why it matters

NFC relay attacks paired with a full-featured RAT represent a meaningful escalation over typical Android banking trojans: SpyNote already provides attackers with broad device control (SMS interception, screen capture, remote access), and adding a real-time NFC relay capability means stolen card data can be used for in-person or point-of-sale fraud almost immediately, not just for one-off account takeover. Any organization with customers who use Android devices for mobile banking, digital wallets, or contactless payments is potentially exposed, and the loan-fraud angle suggests attackers are also targeting victims' broader financial identity, not just card data.

What defenders should watch for

  • Mobile threat defense / MDM telemetry for sideloaded APKs requesting NFC, Accessibility Service, and device-admin permissions in combination — a common pattern for both RAT and relay tooling.
  • Fraud/anti-fraud teams should watch for anomalous card-present transactions closely following account access from unfamiliar Android devices, and for loan or credit applications submitted shortly after a suspected malware infection.
  • SOC teams monitoring EDR/MDM alerts for known SpyNote indicators (C2 patterns, package names, permission requests) as a starting point, pending further IOC publication from the vendor community.
  • User-awareness guidance: discourage sideloading APKs outside official app stores, and flag apps requesting NFC access without an obvious legitimate use case.

Developing story

This is early reporting on a net-new malware combination with limited technical detail publicly available at this time — no CVE is associated with this campaign, and indicators of compromise, distribution vectors, and full technical analysis had not yet been published as of this writing. We will track this story for updates. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.