Affected Systems

Android devices in Czechia, Slovakia, and Slovenia. WindRelay NFC relay malware deployed alongside SpyNote RAT (and variants SpyMax, CypherRAT). 24 WindRelay samples identified on VirusTotal from November 2025 to July 2026. Targets users tricked into sideloading APKs via social engineering phone calls impersonating bank employees.

Exploitation Status

Active exploitation confirmed. Group-IB investigated live incident where attackers completed fraud in 13-minute phone call. WindRelay samples actively communicating with four C2 IP addresses. Campaign targeting Central European banking customers ongoing since at least November 2025.

Business Impact

Attackers gain full remote access to Android devices, relay live NFC payment card data (including PINs and transaction authentication), and execute unauthorized loan applications through banking apps. Entire attack chain completes in minutes during single social engineering call. Financial institutions in affected regions face direct fraud losses. SpyNote also exfiltrates banking credentials, 2FA codes, SMS, GPS location, and enables microphone/camera surveillance. No CVE assigned; threat relies on social engineering rather than technical vulnerability.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Block known WindRelay C2 IP addresses identified by Group-IB at network perimeter and monitor for NFC-related Android malware IOCs from threat intelligence feeds
  • Deploy mobile threat defense (MTD) solutions on corporate Android devices to detect SpyNote, SpyMax, CypherRAT, and WindRelay variants via behavioral analysis and accessibility service abuse detection
  • Implement user awareness training focused on bank impersonation calls and dangers of sideloading APKs or granting Accessibility Service permissions to unknown apps
  • For financial institutions in Czechia, Slovakia, Slovenia: enhance fraud detection rules for rapid loan origination and card transactions occurring within short timeframes, especially following customer service calls
  • Restrict Android device policies to block app installation from unknown sources (ADB, third-party stores) and flag NFC permission requests for review on managed devices