ELSEIF
Your brief EB
433 stories from 95 feeds 252 clusters Refreshed 4 minutes ago next pull 17:36

TECH Signal 439

WindRelay campaign relays live NFC card data through victim's Android phone within 13 minutes

Group-IB discovered a fraud campaign called WindRelay that combines social engineering phone calls, SpyNote RAT, and NFC relay malware to capture live EMV transaction data from Android users and authorize fraudulent payments before banks can intervene.

WHY IT MATTERS

This attack turns the victim's own device into a relay for genuine card-present transactions, making the fraud nearly indistinguishable from legitimate activity because the real card chip completes an authentic handshake with the terminal. The 13-minute window from initial call to cash-out leaves almost no time for automated fraud detection or customer intervention.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Attackers pose as bank helpdesk staff and guide victims to install SpyNote RAT, which silently drops WindRelay NFC relay malware during the same call.

02

WindRelay captures live EMV APDU exchange data when victims tap their card and enter their PIN, and the attacker relays this to a second device for fraudulent purchases or ATM withdrawals.

03

Group-IB observed 23 WindRelay samples on VirusTotal between November 2025 and July 2026 targeting victims in Czechia, Slovakia, and Slovenia, with personalized builds suggesting pre-attack reconnaissance.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles Smooth-talking fraudsters clone contactless cards, authorize payments in just 13 minutes Open ↗