WindRelay, an Android NFC relay malware, is being used with the SpyNote RAT to steal payment card data and enable real-time fraudulent transactions. Group-IB says attackers impersonated bank staff, tricked victims into sideloading a malicious app, and completed the fraud in a 13-minute call. #WindRelay #SpyNote #GroupIB
Keypoints
- WindRelay and SpyNote were used together in a real-world Android fraud campaign.
- Attackers posed as bank employees to pressure victims into installing a malicious app.
- The SpyNote RAT gave attackers remote access and helped install WindRelay silently.
- WindRelay relayed live NFC card data so attackers could make real purchases.
- Group-IB linked the activity to targets in Czechia, Slovakia, and Slovenia.