Smooth-talking fraudsters clone contactless cards, authorize payments in just 13 minutes
Social engineering and malware combine to enable financial fraud before banks have time to act
A sophisticated social engineering campaign, dubbed WindRelay, has been discovered targeting Android users in Europe, according to security firm Group-IB. The operation involves multiple stages, including convincing the victim to install two pieces of malware - SpyNote, a remote access trojan (RAT), and WindRelay, an NFC relay malware.
The attackers impersonate bank helpdesk employees to gain the victim's trust, then install the malware on their Android device, all while the victim is on the phone. Once the RAT and NFC relay malware are installed, the attacker quietly captures the victim's contactless card details during a legitimate transaction. The attacker then uses these details to make unauthorized payments or withdrawals, sometimes even accessing the victim's banking app to take out loans in their name.
The attackers have been observed using multiple channels, including digital loans and card-present purchases, highlighting the evolving nature of modern fraud.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.