13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
Brief
A new Android fraud operation shows how quickly a convincing phone call can turn into financial loss.
The campaign combines the SpyNote remote-control tool with WindRelay, a newly tracked NFC relay malware family. Together, they give criminals access to a victim’s banking app and physical payment card in one short session.
The attack starts with a caller posing as a bank employee and claiming there is a problem with the customer’s card.
The victim is persuaded to install an app and remains on the call while the criminal takes control.
In the investigated case, a loan was issued and card data relayed for fraudulent purchases within 13 minutes.
Analysts at Group-IB identified the malware pairing during an investigation supported by its fraud-protection team.
