Cybersecurity firm Group-IB has identified a new Android NFC relay malware called WindRelay, which operates in conjunction with the SpyNote remote administration tool (RAT). This malware duo is designed to steal credit card information and facilitate fraudulent activities, including taking out loans in the victim's name.
The attack typically begins with a social engineering tactic where a fraudster impersonates a bank employee and contacts the victim. The victim is then instructed to sideload the SpyNote RAT, disguised as a legitimate application, and grant it Accessibility Service permissions. This grants the attacker remote access to the Android device. The attacker then installs WindRelay without further interaction, using the banking app to secure a loan in the victim's name. Victims are also told to tap their payment card on the phone and enter their PIN, allowing WindRelay to relay the live NFC exchange, including transaction-specific authentication data, to the attacker's device for fraudulent purchases.
Group-IB's investigation revealed that the entire fraudulent activity, from initial contact to transaction approval, can occur within a 13-minute phone call. This method allows attackers to commit fraud solely through social engineering, bypassing the need for modern Android malware features like live screen sharing or VNC. The combination of SpyNote and WindRelay provides both device access for banking transactions and a direct cash-out channel for attackers.
Android NFC malware is an increasing concern, with other families like NFCShare, NGate, SuperCard X, and RelayNFC also demonstrating similar capabilities. These attacks typically involve victims installing a malicious app, granting NFC access, and then being socially engineered into tapping their payment card against the compromised phone. The phone captures and transmits card data to the attacker, enabling various forms of financial theft.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new Android NFC relay malware, WindRelay, is being used with the SpyNote remote administration tool (RAT) to steal credit card data and take out loans in victims' names. This combination allows attackers to gain remote access to devices and relay live NFC transactions, enabling real-time financial fraud.