Are your company cards at risk? Android malware cloning cards highlights just how creative threat actors can become when targeting your financial data. Learn more about it here if your team uses wireless payments regularly.
Android Users Beware
The threat intelligence specialists at Group-IB recently discovered malicious software that relies heavily on advanced "vishing" (voice phishing) techniques. Rather than sending out mass spam blasts, threat actors target specific individuals over the phone.
This malware, dubbed "WindRelay" by Group-IB, primarily wreaked havoc in Central and Eastern Europe. The researchers identified 23 WindRelay samples uploaded to VirusTotal, all tied to campaigns in Czechia, Slovakia, and Slovenia. Common targets include both physical, contactless EMV credit or debit cards and mobile banking apps.
Because the attack vector relies on exploiting ecosystem flexibility and the ability to download apps outside official channels, this malware typically targets users on Android.
What Does a WindRelay Attack Look Like?
Android malware cloning cards demonstrates why mobile security matters. Here's how threat actors might infect devices with WindRelay.
Step 1: Reconnaissance
Before the attack even begins, bad actors quietly harvest background information on their target, from their name and phone number to their banking details. This prep work lets them build a custom psychological profile so they know exactly how to approach the individual later.
Step 2: Social Engineering
Armed with personal details, the criminals place a live phone call, posing as bank representatives. They trick the victim into downloading a Remote Access Trojan (RAT) called "SpyNote" from outside the official store, and it's cleverly customized to display the victim's name rather than a generic brand name.
Step 3: Payload Installation
Once SpyNote becomes active, the attacker can use its remote access capabilities to quietly install Near Field Communication (NFC) relay malware.
NFC is wireless technology that allows devices to communicate through close contact. So, instead of relying on banking card theft, attackers can capture NFC activity on a victim's phone and relay it in real time to their own device.
Step 4: The Card Tap
The scammer convinces the target to verify their identity or fix an account issue by tapping their physical bank card against the back of their own phone and entering their PIN. The target thinks they are safe because they never hand the card to anyone else.
Step 5: Live Relaying and Theft
As soon as the card touches the phone, WindRelay reads the NFC chip data and streams it live over the internet to a second device held by an attacker near a contactless payment terminal. The criminals use this streamed data to buy items instantly while the victim is still on the phone.
Protect Your Company From Contactless Card Cloning
Cyberthreats are constantly evolving, and social engineering remains a powerful attack vector. That's why an informed team is one of your best defenses.
Educate employees on threats, such as Android malware that clones cards and facilitates unauthorized real-time transactions. Encourage awareness, vigilance, and the reporting of unusual activity to stay ahead of criminals who target businesses daily.


