Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes
Date:
Thu, 13 Aug 2026 15:20:00 +0000
Description:
Crooks are calling victims on the phone and installing POS malware on their smartphones.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers Victims installed personalized RATs and NFC malware, enabling realtime card theft Attacks were highly targeted across Eastern Europe, with only a few individuals hit
Hackers are turning peoples smartphones into malicious Point of Sale (POS) devices and stealing their money directly from their payment cards, experts have warned.
Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign WindRelay , after the custom-built malware
used during the attacks. The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victims identity, phone number, and likely other details. Although the researchers dont discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks. Latest Videos
From TechRadar Watch full video here: Vishing and malware After learning a little bit about their target, the attackers get to work. They first prepare
a remote access trojan (RAT) named SpyNote. They personalize the label with the victims own name (instead of it being a generic or impersonated brand),
to build trust with their victim:
Such tactics are more effective at weakening a victims natural defenses and suspicions, the researchers noted in the report. It removes the one cue
people are trained to check before installing something unfamiliar a strange or generic app name right at the moment theyre most likely to hesitate. You may like Hundreds of Android banking and crypto apps hit by dangerous new Rokarolla malware Security experts warn of AI-boosted scam campaigns that can trick even the smartest victims Hackers are hijacking legitimate news
websites and reviews to drum up publicity
Then, they call the victim on the phone and introduce themselves as employees of their targets bank. They claim the victim has a problem with their bank card, and instruct them to deploy SpyNote through the devices package installer (the standard way to sideload apps outside an official app store).
SpyNote is a classic RAT that the attackers then use to deploy stage-two malware themselves. In this next step, they personally (as opposed to having the victim do it) install WindRelay, custom near-field communication (NFC) malware designed to capture contactless payment card data in real-time, when
a card is tapped against the phone. Are you a pro? Subscribe to our
newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
In other words, the malware turns the smartphone into a POS, and when a
victim taps their card against it, the information is relayed to an attackers terminal. Vishing + malware Vishing + malware combo is nothing new. Weve seen it deployed numerous times before, and ShinyHunters are probably the shiniest example of the practice (pun definitely intended). Over the last couple of years, ShinyHunters have been calling their victims on the phone, impersonating the IT department, and getting their victims to log in via fake login portals which relay the credentials to the attackers.
They then use the credentials to access their victims SaaS products, exfiltrate as much sensitive data as possible, and then demand ransom in exchange for deleting the stolen files. What to read next ClickLock Stealer tries to trick macOS users into revealing their passwords Hackers are using TikTok videos offering 'free Spotify Premium' to spread malware and steal passwords New 'scareware' attack hits 2.8 million victims, pretending to lock them out of your browser
This new campaign, however, is a testament to the techniques evolution. While ShinyHunters operatives only stay on the phone call until the victim logs in, these crooks remain on the line for as long as it takes. Group-IB says the average call lasts around 13 minutes, and by that moment, the victim will
have installed both SpyNote and WindRelay, and has tapped their bank card against the phone, making unwanted payments.
In at least one case, the attackers successfully applied for a loan at the victims bank, stealing not only the money they had on their account, but also money they would have earned in the future.
The identity of the attackers is unknown at the time. We also dont know exactly how many victims there were, but given the highly personalized nature of the attack, its safe to assume that there were only a handful.
Group-IB says it observed attacks in Czechia, Slovakia, and Slovenia, suggesting a threat actor focused primarily on Eastern European victims. The researchers also said they identified 23 samples uploaded to VirusTotal between November 2025 and July 2026, meaning the campaign was active for approximately seven months, targeting 23 individuals.
The samples mimic various institutions from the targeted countries and
contain text in the language of each targeted country, the researchers said. Some samples contain personalized UI elements and labels, such as the name of the victim, similar to the personalized RAT. This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims.
Group-IB says users should treat personalized app labels as a red flag and should apply extra friction to loan applications. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/android-users-targeted-by-new-windrelay -malware-which-can-clone-contactless-cards-in-just-13-minutes
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)