TGViewer
Group-IB Group-IB @group_ib · 2.52K subscribers
Post #983 847
☎️ A live phone call. A remote access trojan. An NFC relay malware.

Group-IB researchers uncovered WindRelay, a previously unseen Android NFC relay malware deployed alongside SpyNote RAT in a live-call fraud scheme.

The investigation reveals how threat actors are combining:
🔹 Social engineering calls with personalized RAT delivery
🔹 Remote sideloading of NFC relay malware
🔹 Real-time interception and relay of EMV card transactions
🔹 23 related samples and four C2 IPs linked to WindRelay activity

The findings also highlight why defenders should look beyond screen-sharing detection and monitor Accessibility Service abuse, sideloaded apps, suspicious permissions, and NFC activity.

👉 Read the full technical analysis.

#AndroidMalware #SpyNoteRAT #WindRelay #FraudPrevention
  • 🔥 5
  • 👍 4
More from @group_ib
  1. Sep 23, 2026🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android bankin…
  2. Sep 17, 2026🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CR…
  3. Sep 14, 2026🚨 Inside the Smishing Triad’s Phishing Cockpit Group-IB’s latest research dives into JWR,…
  4. Sep 9, 2026🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelte…
  5. Sep 3, 2026🚨 Outsider Phishing Kit: a resilient PhaaS threat Group-IB researchers uncovered the Outs…
  6. Sep 1, 2026🚨 Cybercrime is evolving, and so is the underground economy behind it. Group-IB has uncov…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →