Smooth-talking fraudsters clone contactless cards, authorize payments in just 13 minutes
Social engineering and malware combine to enable financial fraud before banks have time to act
A new cybercrime scheme utilizes social engineering and malware to clone contactless cards and make payments within just 13 minutes. The operation, identified as WindRelay, was uncovered by Group-IB and targeted European Android users. The attack relies on a social engineer tricking victims into installing SpyNote, a remote access trojan (RAT), through a convincing phone call disguised as a bank helpdesk.
After installing SpyNote, the attacker installs WindRelay on the infected device, capturing live EMV APDU exchanges between the victim's payment card and the NFC-enabled smartphone. With this data, the attacker can authorize fraudulent charges using the victim's PIN. The malware can also be used to access the victim's banking app and take out loans.
Group-IB observed 23 WindRelay-related samples uploaded to VirusTotal between November 2025 and July 2026, targeting victims in Czechia, Slovakia, and Slovenia, but failed to identify the attacker(s).
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.