{
  "id": 778210,
  "title": "Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes",
  "url": "https://urgent.news/2026/08/13/android-users-targeted-by-new-windrelay-malware-which-can-clone",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-13T15:20:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/android-users-targeted-by-new-windrelay-malware-which-can-clone-contactless-cards-in-just-13-minutes"
  },
  "original_language": "en",
  "account": "A new malware dubbed WindRelay is targeting Android users in Eastern Europe, capable of cloning contactless bank cards in just 13 minutes. This highly sophisticated attack employs vishing, or voice phishing, combined with custom-built malware to turn smartphones into malicious Point of Sale (POS) devices. The campaign, named after the custom malware used, begins with reconnaissance to identify the victim's identity and phone number, often obtained from previous data breaches. Attackers then use a personalized remote access trojan (RAT) called SpyNote to gain the victim's trust, claiming there's an issue with their bank card and instructing them to install the RAT via their device's package installer. After installing SpyNote, attackers deploy WindRelay, a custom NFC malware designed to capture contactless payment card data in real-time. This turns the smartphone into a POS, allowing attackers to steal money directly from the victim's payment card when it's tapped against the phone. The attack is highly targeted, with only a few individuals affected, primarily in Czechia, Slovakia, and Slovenia. Victims were called by the attackers, who impersonated bank employees, and the average call lasted around 13 minutes, giving the victim enough time to install both SpyNote and WindRelay. The stolen card data is then relayed to an attacker's terminal, enabling unauthorized transactions and even successful loan applications.",
  "summary": "Crooks are calling victims on the phone and installing POS malware on their smartphones.",
  "key_points": [
    "Android users in Eastern Europe targeted by WindRelay malware",
    "Clones contactless bank cards in 13 minutes using vishing and SpyNote",
    "Primarily affects Czechia, Slovakia, and Slovenia"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}