Tech

Smooth-talking fraudsters clone contactless cards, authorize payments in just 13 minutes

Published

on

cyber-crime

Social engineering and malware combine to enable financial fraud before banks have time to act

A new social engineering and malware campaign targets Android users, stealing card details to make payments or withdraw cash. Group-IB discovered the campaign, calling it WindRelay, and found that several successful attacks were carried out on European victims within the space of a 13-minute phone call.

The attack relies on a skilled social engineer walking the victim through the process and two malware strains: An NFC relay malware called WindRelay, first discovered in August 2025, and SpyNote, a remote access trojan (RAT) that was leaked on cybercrime forums as far back as 2016.

Advertisement

It goes like this: The attacker calls the target while posing as a helpdesk employee at their bank, convincing the victim-in-waiting that there is a problem with their payment card.

While still on the phone, the attacker gets the target to install a version of SpyNote on their Android device. The file name includes the target’s name, which the researchers said could suggest that each target is singled out specifically, and a degree of reconnaissance has to be carried out prior to the attack.

Once installed, the attacker quickly uses the RAT’s remote access to quietly install WindRelay on the attacker’s device without their knowledge or input, all while the call was ongoing. 

The attacker then instructs the target to tap their payment card on their NFC-enabled smartphone and, when prompted, enter their PIN. 

Advertisement

WindRelay then captures the data from that interaction between the card’s chip and the reader, similarly to how genuine point-of-sale machines authorize contactless payments. This is known as a live EMV APDU exchange.

In order to fraudulently make payments using this data – without physical access to the payment card or the cardholder – the attacker must have a second device capable of using this data to authorize a payment. 

This could be a second Android smartphone capable of loading this data and transmitting it to an attacker-controlled POS terminal, which is linked to a fraudulent merchant bank account, or an ATM.

The attacker then uses the captured live exchange data to execute fraudulent charges on the victim’s card, authorized using the PIN they entered during the call.

Advertisement

Group-IB said in its write-up: “In effect, the victim’s card and the real terminal are still talking directly to each other – the fraudster’s setup is just an invisible relay in between, passing the exchange back and forth across a distance. 

“Because the terminal is genuinely completing a live handshake with a real card, the transaction goes through and processes the withdrawal or purchase as normal.”

Doubling down on their access, Group-IB also noted that the attackers in one instance used their RAT access to access the victim’s banking app and take out loans in their name.

The researchers also said they observed 23 WindRelay-related samples uploaded to VirusTotal between November 2025 and July 2026, with signs pointing toward targeting victims in Czechia, Slovakia, and Slovenia. 

Advertisement

They were not able to pin down the attacker(s) behind the malware, although they said it was independently developed and the samples they saw uploaded to VirusTotal all contained unique UI elements, such as the victim’s name, just like with the RAT.

“This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims,” said Group-IB.

“This case shows that modern fraud rarely relies on one technique,” it added. “Here, the fraudster combined three capabilities in a single session – a live social engineering call, a personalized RAT for remote device control, and an NFC relay malware for physical cash-out. 

“The fraudster also used these capabilities to hit two separate payout channels – a digital loan and card-present purchases – before the bank or victim could react.”

Advertisement

The attack is similar to previous NFC relay-related campaigns, such as NGate in 2024 (and more recently in 2026), and Ghost Tap, the techniques involved in which closely align with WindRelay.

Ghost Tap, also discovered in 2024, relies on a Chinese malware sold throughout the country’s cybercrime Telegram communities, and according to Group-IB, it was responsible for losses exceeding $355,000 between November 2024 and August 2025 alone. ®

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version