WindRelay Android Malware Exploits NFC Capabilities for Contactless Payment Fraud
WindRelay is a new Android malware family that uses NFC relaying capabilities to intercept contactless payment data, combined with SpyNote RAT for remote access and social engineering. The malware enables real-time fraud by turning victims' devices into payment proxies, allowing cybercriminals to perform unauthorized transactions without detection.
A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme.
The purpose-built malware, according to Group-IB, is designed to capture live card data via NFC and transmit it to fraudsters in real time. It was first detected in
*** END OF TRANSMISSION ***