started · updated
Android malware uses SpyNote and WindRelay to steal credit card data
Cybersecurity experts at Group-IB have identified a new Android malware attack involving the combination of SpyNote RAT and WindRelay to steal credit card data and perform fraudulent transactions in real time.
The attack utilizes social engineering, where criminals pose as bank employees during a phone call to convince victims to sideload a malicious APK file. Once SpyNote is installed, attackers gain remote access to the device, allowing them to steal credentials, track locations, and intercept communications.
During the call, attackers use WindRelay to exploit the device's NFC chip. They instruct the victim to bring their credit card close to the smartphone and enter their PIN, effectively transmitting the data to a remote server to clone the card. This process can allow criminals to authorize payments or even take out loans in the victim's name while the user remains on the line.