Android Malware Duo SpyNote and WindRelay Used to Steal Loans and Relay Card Payments
Security researchers at Group-IB have uncovered a sophisticated Android fraud campaign combining two malware tools, SpyNote and WindRelay, to commit financial theft. Attackers impersonate bank staff over phone calls and trick victims into sideloading a personalised SpyNote APK and granting Accessibility Service permissions. Once installed, SpyNote silently deploys WindRelay and remotely operates the victim's official banking app to take out loans in their name. WindRelay captures NFC card data in real time when the victim taps their physical card on their phone, relaying it to the attacker's device, which emulates the card at a legitimate point-of-sale terminal. The attack requires no root access and exploits standard Android features, making it difficult for banks to distinguish fraudulent activity from normal device behaviour.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in