☎️ A live phone call. A remote access trojan. An NFC relay malware.
Group-IB researchers uncovered WindRelay, a previously unseen Android NFC relay malware deployed alongside SpyNote RAT in a live-call fraud scheme.
The investigation reveals how threat actors are combining:
🔹 Social engineering calls with personalized RAT delivery
🔹 Remote sideloading of NFC relay malware
🔹 Real-time interception and relay of EMV card transactions
🔹 23 related samples and four C2 IPs linked to WindRelay activity
The findings also highlight why defenders should look beyond screen-sharing detection and monitor Accessibility Service abuse, sideloaded apps, suspicious permissions, and NFC activity.
👉 Read the full technical analysis.
#AndroidMalware #SpyNoteRAT #WindRelay #FraudPrevention
Post #983
847

- 🔥 5
- 👍 4