The 13-Minute Fraud Window: WindRelay Exposes Legacy Payment Gaps

AI-generated image · US National Wire
A sophisticated relay attack allows fraudsters to clone contactless cards and drain accounts before banks can intervene.
A new campaign discovered by Group-IB reveals a systemic vulnerability in real-time fraud detection, where attackers can authorize fraudulent payments in as little as 13 minutes, as first reported by The Register. The operation—dubbed WindRelay—combines social engineering with a two-pronged malware attack to bypass traditional security rails.
The process begins with a fraudster posing as a bank helpdesk employee to convince an Android user to install SpyNote, a remote access trojan (RAT). While the victim remains on the phone, the attacker uses the RAT to install WindRelay, an NFC relay malware. The attacker then instructs the victim to tap their payment card on their smartphone and enter their PIN.
WindRelay captures the live EMV APDU exchange between the card's chip and the reader. This data is then transmitted to a second device linked to a fraudulent merchant bank account or an ATM. Because the system processes this as a genuine live handshake with a physical card, the transaction is authorized as normal. Group-IB noted that in one instance, attackers used RAT access to enter a victim's banking app and secure loans in the victim's name.
Group-IB identified 23 WindRelay samples on VirusTotal between November 2025 and July 2026, specifically targeting victims in Slovenia, Slovakia, and Czechia. The researchers noted that the malware appears to be dynamically tailored to individual victims. This technique mirrors previous NFC relay campaigns like Ghost Tap and NGate; Group-IB reports that Ghost Tap alone caused losses exceeding $355,000 between November 2024 and August 2025.

