Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes
Crooks are calling victims on the phone and installing POS malware on their smartphones.
A new malware dubbed WindRelay is targeting Android users in Eastern Europe, capable of cloning contactless bank cards in just 13 minutes. This highly sophisticated attack employs vishing, or voice phishing, combined with custom-built malware to turn smartphones into malicious Point of Sale (POS) devices. The campaign, named after the custom malware used, begins with reconnaissance to identify the victim's identity and phone number, often obtained from previous data breaches.
Attackers then use a personalized remote access trojan (RAT) called SpyNote to gain the victim's trust, claiming there's an issue with their bank card and instructing them to install the RAT via their device's package installer. After installing SpyNote, attackers deploy WindRelay, a custom NFC malware designed to capture contactless payment card data in real-time.
This turns the smartphone into a POS, allowing attackers to steal money directly from the victim's payment card when it's tapped against the phone. The attack is highly targeted, with only a few individuals affected, primarily in Czechia, Slovakia, and Slovenia. Victims were called by the attackers, who impersonated bank employees, and the average call lasted around 13 minutes, giving the victim enough time to install both SpyNote and WindRelay.
The stolen card data is then relayed to an attacker's terminal, enabling unauthorized transactions and even successful loan applications.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.