HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

WindRelay Android Malware Relays Live NFC Card Data to Fraudsters via Remote Access Trojan

Group‑IB uncovered WindRelay, an Android malware that captures live NFC payment‑card information and streams it to attackers after victims install a customized SpyNote RAT during a phone‑call scam. The campaign demonstrates how weak mobile security and insufficient user awareness can lead to confirmed card‑data exposure, a scenario SOC 2 controls aim to prevent and evidence.

LiveThreat™ Intelligence · 📅 August 14, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

WindRelay Android Malware Relays Live NFC Card Data to Fraudsters via Remote‑Access Trojan

What Happened — Group‑IB researchers identified WindRelay, an Android malware family that captures live NFC payment‑card data and streams it to attackers in real time. The malware is installed after a victim answers a phone call, installs a customized SpyNote remote‑access trojan, and then receives the second stage WindRelay payload without further interaction.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 requires documented security‑awareness training; this campaign shows how a single phone‑call can bypass technical controls.
  • SOC 2 CC7.1 mandates controls over mobile device permissions and app vetting; unrestricted NFC and remote‑access permissions enabled the theft.
  • Continuous monitoring of privileged app installations provides audit evidence that such malicious activity would be detected and contained.

Who Is Affected — Primarily financial‑services customers in the Czech Republic, Slovakia, and Slovenia, but the technique is applicable to any organization that allows employees to use personal Android devices for banking or payment functions.

Recommended Actions

  • Deploy organization‑wide security‑awareness training that includes phone‑based phishing simulations.
  • Enforce mobile‑device‑management (MDM) policies that restrict NFC use and block unsigned remote‑access apps.
  • Implement continuous monitoring for anomalous app behavior and outbound C2 traffic on managed devices. Source: Help Net Security

Technical Notes

  • Attack chain: social‑engineering phone call → SpyNote RAT (custom label, name, package) → WindRelay NFC relay app (requires contacts and system‑inspection permissions).
  • Four C2 IPs observed; 23 samples submitted to VirusTotal (Nov 2025 – Jul 2026).
  • Data exfiltrated: live card PAN, expiration, and PIN entered by victim. Source: Help Net Security
📰 Original Source
https://www.helpnetsecurity.com/2026/08/14/windrelay-android-nfc-relay-malware/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →