Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes

https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-2121-80.jpg
  • WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers
  • Victims installed personalized RATs and NFC malware, enabling real‑time card theft
  • Attacks were highly targeted across Eastern Europe, with only a few individuals hit

Hackers are turning people’s smartphones into malicious Point of Sale (POS) devices and stealing their money directly from their payment cards, experts have warned.

Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign WindRelay, after the custom-built malware used during the attacks.

The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victim’s identity, phone number, and likely other details. Although the researchers don’t discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks.

Vishing and malware

After learning...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more