Fast‑Talking Scammers Clone Contactless Cards, Steal Payments in Under 13 Minutes

0
5

Key Takeaways

  • A newly identified Android malware campaign, dubbed WindRelay, combines social engineering, a remote‑access trojan (SpyNote), and an NFC‑relay tool to steal payment card data in real time.
  • Attackers pose as bank help‑desk staff, convince victims to install SpyNote during a short (≈13‑minute) phone call, then silently push WindRelay to capture live EMV APDU exchanges when the victim taps their card and enters the PIN.
  • The captured data is replayed on a second attacker‑controlled device to authorize fraudulent card‑present purchases or ATM withdrawals, and in some cases the RAT is used to fraudulently take out loans via the victim’s banking app.
  • Victims have been observed primarily in Czechia, Slovakia, and Slovenia; 23 WindRelay‑related samples appeared on VirusTotal between November 2025 and July 2026, each bearing unique UI elements (e.g., the victim’s name) indicating highly tailored, dynamically generated malware.
  • The campaign mirrors earlier NFC‑relay attacks such as NGate (2024/2026) and Ghost Tap, underscoring a trend where fraudsters blend live voice deception, custom RATs, and NFC relay techniques to bypass traditional bank fraud controls before victims or institutions can react.

Overview of the WindRelay Campaign
Group‑IB uncovered a sophisticated fraud operation targeting Android users in Europe, which they named WindRelay. The campaign integrates three distinct capabilities: a convincing social‑engineering phone call, a personalized remote‑access trojan (SpyNote) for device control, and an NFC‑relay malware (WindRelay) that captures live card‑chip communication. By orchestrating these elements within a single, brief interaction, attackers can steal payment data and monetize it almost instantly, leaving banks little time to intervene.

How the Attack Begins: The Social‑Engineering Call
The fraudster initiates contact by impersonating a help‑desk representative from the victim’s bank, claiming there is an issue with the victim’s payment card. This pretext creates urgency and trust, prompting the target to follow instructions without suspicion. The call is deliberately kept short—around 13 minutes—to limit the victim’s opportunity to verify the caller’s identity or seek external advice, thereby increasing the likelihood of compliance.

Delivery of the Remote‑Access Trojan (SpyNote)
While still on the line, the attacker convinces the victim to install a SpyNote variant whose file name includes the victim’s personal name, suggesting prior reconnaissance. Once installed, SpyNote grants the attacker full remote control over the Android device, enabling silent installation of additional malware, extraction of data, and manipulation of apps without the victim’s awareness.

Silent Deployment of WindRelay NFC Relay Malware
Using the RAT’s remote capabilities, the attacker covertly installs WindRelay on the victim’s device during the ongoing call. WindRelay functions as an NFC relay: it intercepts the communication between the victim’s payment card (when tapped to the phone) and the phone’s NFC reader, capturing the live EMV APDU exchange that normally occurs at a point‑of‑sale terminal. Because the victim believes they are performing a legitimate contactless transaction, they willingly enter their PIN, which WindRelay also records.

Replaying Captured Data for Fraudulent Transactions
The stolen APDU exchange and PIN are transmitted to a second attacker‑controlled device—often another Android smartphone configured to emulate a POS terminal or ATM. This device replays the captured data to a fraudulent merchant account linked to the attacker’s bank, authorizing a purchase or cash withdrawal as if the genuine card were present. Since the terminal completes a legitimate handshake with the real card, the transaction appears authentic to the issuing bank and processes normally.

Exploiting the RAT for Additional Financial Abuse
In at least one observed incident, the attackers leveraged their SpyNote access to open the victim’s banking application and fraudulently obtain loans in the victim’s name. This demonstrates that the RAT is not merely a conduit for NFC relay malware but a versatile tool capable of initiating various types of financial fraud, amplifying the potential damage per compromised device.

Geographic Focus and Malware Characteristics
Group‑IB identified 23 WindRelay‑related samples uploaded to VirusTotal between November 2025 and July 2026, with clustering indicating primary targets in Czechia, Slovakia, and Slovenia. Each sample contained unique UI elements—most notably the victim’s name—suggesting the threat actor dynamically builds customized malware for each target rather than distributing a static binary. This level of personalization implies significant pre‑attack reconnaissance and a modular malware development pipeline.

Comparison to Prior NFC‑Relay Campaigns
WindRelay’s tactics closely resemble earlier NFC‑relay operations such as NGate (observed in 2024 and resurfacing in 2026) and Ghost Tap. Ghost Tap, which relied on a Chinese malware spread via cybercrime Telegram groups, caused losses exceeding $355,000 between November 2024 and August 2025. The similarities highlight an evolving fraud ecosystem where attackers continually refine NFC‑relay techniques, combining them with social engineering and custom RATs to increase success rates and evade detection.

Implications for Banks and Users
The WindRelay case illustrates that modern payment fraud rarely depends on a single vector; instead, threat actors orchestrate multi‑stage attacks that exploit human trust, device vulnerabilities, and NFC technology simultaneously. Banks must enhance real‑time anomaly detection for contactless transactions, implement stricter app‑installation policies (e.g., blocking unknown sources), and educate customers about unsolicited calls requesting software installation. Users, in turn, should verify caller identity through official channels, refrain from installing apps based on unverified requests, and monitor account activity closely for unauthorized loans or transactions. By addressing both the technical and human elements of such attacks, the window of opportunity for fraudsters can be significantly reduced.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here