< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 2 sources · 22 days · First seen · Last updated

Android malware and NFC relay fraud campaigns

Overview

Security researchers have identified sophisticated Android malware campaigns targeting users through social engineering and remote access tools.

Initial findings detailed a scheme involving the SpyNote remote access trojan (RAT) and WindRelay, a specialized NFC malware. In this campaign, attackers use vishing—posing as bank employees—to trick victims in Eastern European countries, such as the Czech Republic, Slovakia, and Slovenia, into sideloading a malicious APK. Once Accessibility Service permissions are granted, attackers can control banking apps to apply for loans or execute NFC relay attacks. These attacks allow criminals to capture real-time NFC communication when a victim taps their physical credit card against the compromised phone, enabling unauthorized purchases at point-of-sale terminals.

Subsequent reports expanded on these threats, identifying additional malware and distribution methods. A second campaign involving the StreamRat malware spreads via paid advertisements on social media platforms like Facebook, Instagram, and TikTok, often promising free streaming services. This campaign has reportedly reached approximately 570,000 users. Additionally, the WindTapper group continues to utilize phone scams and WindRelay malware to facilitate real-time unauthorized contactless payments.

Entities

Android · WindRelay · WindRelay · Group-IB · ThreatFabric

Timeline

  1. 8 days ago

    [TECHNOLOGY] 2 sources
    Android malware campaigns target users via social media and phone scams

    New Android malware campaigns, including StreamRat and WindRelay, are targeting users via social media ads and phone scams to steal credentials and facilitate contactless payment fraud.

  2. 30 days ago

    [TECHNOLOGY] 4 sources
    WindRelay malware turns Android phones into fraudulent payment devices

    A sophisticated malware campaign uses SpyNote and WindRelay to turn Android phones into fraudulent POS devices, enabling attackers to steal loans and relay NFC credit card data in real-time.

Sources

topky.sk · vosveteit.zoznam.sk