← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 12, 2026 · 12:00via Cyber Security News

13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts

Brief

A new Android fraud operation shows how quickly a convincing phone call can turn into financial loss.

The campaign combines the SpyNote remote-control tool with WindRelay, a newly tracked NFC relay malware family. Together, they give criminals access to a victim’s banking app and physical payment card in one short session.

The attack starts with a caller posing as a bank employee and claiming there is a problem with the customer’s card.

The victim is persuaded to install an app and remains on the call while the criminal takes control.

In the investigated case, a loan was issued and card data relayed for fraudulent purchases within 13 minutes.

Analysts at Group-IB identified the malware pairing during an investigation supported by its fraud-protection team.

Read more on Cyber Security News