cyber-crime
Social engineering and malware combine to enable financial fraud before banks have time to act
A new social engineering and malware campaign targets Android users, stealing card details to make payments or withdraw cash. Group-IB discovered the campaign, calling it WindRelay, and found that several successful attacks were carried out on European victims within the space of a 13-minute phone call.The attack relies on a skilled social engineer walking the victim through the process and two malware strains: An NFC relay malware called WindRelay, first discovered in August 2025, and SpyNote, a remote access trojan (RAT) that was leaked on cybercrime forums as far back as 2016.It goes like this: The attacker calls the target while posing as a helpdesk employee at their bank, convincing the victim-in-waiting that there is a problem with their payment card.
While still on the phone, the attacker gets the target to install a version of SpyNote on their Android device. The file name includes the target's name, which the researchers said could suggest that each target is singled out specifically, and a degree of reconnaissance has to be carried out prior to the attack.
Once installed, the attacker quickly uses the RAT's remote access to quietly install WindRelay on the attacker's device without their knowledge or input, all while the call was ongoing. The attacker then instructs the target to tap their payment card on their NFC-enabled smartphone and, when prompted, enter their PIN. WindRelay then captures the data from that interaction between the card's chip and the reader, similarly to how genuine point-of-sale machines authorize contactless payments. This is known as a live EMV APDU exchange.In order to fraudulently make payments using this data – without physical access to the payment card or the cardholder – the attacker must have a second device capable of using this data to authorize a payment. This could be a second Android smartphone capable of loading this data and transmitting it to an attacker-controlled POS terminal, which is linked to a fraudulent merchant bank account, or an ATM.The attacker then uses the captured live exchange data to execute fraudulent charges on the victim's card, authorized using the PIN they entered during the call.Group-IB said in its write-up: "In effect, the victim's card and the real terminal are still talking directly to each other – the fraudster's setup is just an invisible relay in between, passing the exchange back and forth across a distance. "Because the terminal is genuinely completing a live handshake with a real card, the transaction goes through and processes the withdrawal or purchase as normal."








