TECH FLOW Svět Androida
← Back to the stream
thehackernews.com · picked by Petr Mišák · 51d ago

WindRelay Android malware for NFC payment fraud expanding to Czech Republic

Source preview: WindRelay Android malware for NFC payment fraud expanding to Czech Republic
AI summary

WindRelay is an Android malware that acts as an NFC relay for contactless payment fraud. It spreads through the SpyNote remote access trojan, enabling attackers to install it without user awareness. Over 20 samples have been detected in Czech Republic, Slovakia, and Slovenia, targeting banking apps and payment cards.

The summary is written by AI from the source; it isn’t the newsroom’s opinion. For details, read the source.

6 people have already opened the source

Tip author’s note

If you think NFC activation requires the phone to be unlocked, think again—combined with SpyNote remote access trojan, that's not the case anymore.

AI questions & answers
How exactly does WindRelay enable payment card fraud?

The malware intercepts NFC signals from a payment card on the infected phone and streams them to the attacker in real time. The attacker can then emulate the card on their own device to make purchases or ATM withdrawals without possessing the physical card.

Why is the SpyNote and WindRelay combination more dangerous than the malware alone?

SpyNote grants the attacker remote access and allows silent installation of WindRelay without further user interaction. Additionally, the attacker can use SpyNote to take out loans or perform other fraud, while WindRelay handles physical card-present purchases.

How do users end up with this malware?

Attackers lure victims through phishing, smishing, or vishing calls with fabricated reasons like identity verification or PIN changes. The distributed app is often personalized with the victim's name to appear more credible.

What advantages does Ghost Tap provide over traditional card fraud methods?

Ghost Tap allows attackers to remain anonymous and scale fraud operations significantly without needing physical access to payment terminals. They leverage the victim's infected phone as a relay point instead.

Questions and answers are written by AI about the topic, not taken from the source; they aren’t the newsroom’s opinion.
We wrote our own article about this
Nový NFC malware WindRelay cílí i na české účty. Z telefonu udělá čtečku vaší platební karty
→
Related from the stream
Mentions
  • WindRelay
  • SpyNote
  • Group-IB
  • NFC
  • Android14
  • Ghost Tap
  • ESET
  • VirusTotal