Smooth-talking fraudsters clone contactless cards, authorize payments in just 13 minutes

https://image.theregister.com/5240227.jpg?imageId=5240227&x=0&y=15.13&cropw=100&croph=84.87&panox=0&panoy=15.13&panow=100&panoh=84.87&width=1200&height=683

Social engineering and malware combine to enable financial fraud before banks have time to act

A new social engineering and malware campaign targets Android users, stealing card details to make payments or withdraw cash. Group-IB discovered the campaign, calling it WindRelay, and found that several successful attacks were carried out on European victims within the space of a 13-minute phone call.

The attack relies on a skilled social engineer walking the victim through the process and two malware strains: An NFC relay malware called WindRelay, first discovered in August 2025, and SpyNote, a remote access trojan (RAT) that was leaked on cybercrime forums as far back as 2016.

It goes like this: The attacker calls the target while posing as a helpdesk employee at their bank, convincing the victim-in-waiting that there is a problem with their payment card.

While still on the phone, the attacker gets the target to...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more