< Back to all clusters
[TECHNOLOGY] · Czechia, Slovakia, Slovenia · 4 sources

started · updated

WindRelay malware turns Android phones into fraudulent payment devices

Security researchers have identified a sophisticated financial fraud campaign involving the combination of SpyNote, a remote access trojan (RAT), and WindRelay, a specialized NFC malware. The attack targets Android users, primarily in Eastern Europe, including the Czech Republic, Slovakia, and Slovenia.

The scheme begins with vishing, where attackers pose as bank employees to trick victims into sideloading a customized SpyNote APK. Once the victim grants Accessibility Service permissions, attackers use remote control to operate banking apps and apply for loans in the victim's name.

Furthermore, the WindRelay malware enables an NFC relay attack. By instructing victims to tap their physical credit cards against their compromised smartphones, attackers can capture real-time NFC communication and relay it to a remote device. This allows the criminals to emulate the victim's card at legitimate point-of-sale (POS) terminals to make unauthorized purchases.

Entities

Android · Group-IB · SpyNote · WindRelay