Overview
- Researchers described a case in which a fraudster used a 13-minute phone call to social-engineer a victim into sideloading a personalized SpyNote RAT that gave the attacker remote control of the device.
- After remote access, the attacker quietly installed a newly identified NFC-relay malware family called WindRelay that turned the phone into a contactless reader and streamed the live NFC exchange to the fraudster's device.
- The streamed NFC data included transaction-specific authentication codes so the fraudster could present the card remotely at a real terminal while the victim remained on the line.
- Group-IB linked roughly two dozen WindRelay samples uploaded to VirusTotal between November 2025 and July 2026 and published its technical write-up on August 12, 2026, prompting immediate detection and prevention guidance for banks and processors.
- Researchers advised banks to flag app installs from non-official sources during active calls and to monitor loan disbursements that coincide with physical card transactions, and they urged users to avoid sideloading apps and to verify bank calls via official numbers.