A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time.
In an incident investigated by the cybersecurity company Group-IB, a fraudster impersonated a bank employee and called the victim under the pretense of a problem with their payment card.
During the call, the threat actor instructed the victim to sideload the SpyNote RAT disguised as a legitimate app and grant it Accessibility Service permissions, giving the attacker remote access to the Android device.
To add credibility, the attacker personalized the malicious app label with the victim's name.
Builder creates victim-specific SpyNote APKs
Source: Group-IB
After gaining remote access to the device through SpyNote, the attacker installed WindRelay without further interaction with the victim and used the banking app to take out a loan in the victim’s name. Additionally, the victim was instructed to tap their payment card on the phone and enter their PIN. WindRelay turned the phone into a fraudulent contactless reader and relayed the live NFC (near-field communication) exchange, including the card’s transaction-specific authentication data, to the attacker’s device. This allowed the attacker to use the card data for purchases at a genuine payment terminal. Group-IB says that the entire activity occurred in a 13-minute phone call, and transactions were approved using the PIN provided by the victim.
Attack chain overview
Source: Group-IB
The researchers highlight that the combination of SpyNote and WindRelay may indicate a toolkit that provides both access to the victim's device for banking transactions and a direct cash-out channel.
... continue reading