Group-IB researchers have identified WindRelay, a new Android malware that captures live payment card data via NFC and relays it to attackers in real time. The malware is paired with the SpyNote RAT, which grants attackers remote access to the infected device, and the attack chain is initiated through social engineering phone calls impersonating bank officials.
Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access trojan, which gives attackers remote access to a victim’s device. Attack chain overview (Source: Group-IB) How the scam unfolds The scam starts with a phone call, in which the fraudster claims to be from the victim’s bank and says … More → The post New Android malware relays bank cards to fraudsters while victims still hold them appeared first on Help Net Security .