WindRelay Android Malware Relays Live NFC Card Data to Fraudsters via Remote‑Access Trojan
What Happened — Group‑IB researchers identified WindRelay, an Android malware family that captures live NFC payment‑card data and streams it to attackers in real time. The malware is installed after a victim answers a phone call, installs a customized SpyNote remote‑access trojan, and then receives the second stage WindRelay payload without further interaction.
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 requires documented security‑awareness training; this campaign shows how a single phone‑call can bypass technical controls.
- SOC 2 CC7.1 mandates controls over mobile device permissions and app vetting; unrestricted NFC and remote‑access permissions enabled the theft.
- Continuous monitoring of privileged app installations provides audit evidence that such malicious activity would be detected and contained.
Who Is Affected — Primarily financial‑services customers in the Czech Republic, Slovakia, and Slovenia, but the technique is applicable to any organization that allows employees to use personal Android devices for banking or payment functions.
Recommended Actions
- Deploy organization‑wide security‑awareness training that includes phone‑based phishing simulations.
- Enforce mobile‑device‑management (MDM) policies that restrict NFC use and block unsigned remote‑access apps.
- Implement continuous monitoring for anomalous app behavior and outbound C2 traffic on managed devices. Source: Help Net Security
Technical Notes
- Attack chain: social‑engineering phone call → SpyNote RAT (custom label, name, package) → WindRelay NFC relay app (requires contacts and system‑inspection permissions).
- Four C2 IPs observed; 23 samples submitted to VirusTotal (Nov 2025 – Jul 2026).
- Data exfiltrated: live card PAN, expiration, and PIN entered by victim. Source: Help Net Security