WindRelay is a previously unseen Android NFC relay malware family documented by Group-IB. It is deployed alongside the SpyNote RAT in live-call social engineering attacks targeting victims in Czechia, Slovakia, and Slovenia. The malware relays an active card in real time, using a two-device relay primitive similar to the Zombie Card attack testbed.