
Group-IB has discovered a new Android malware named WindRelay. It turns victims’ phones into fake card readers and instantly relays transactions to scammers located far away.
Key Points:
• Scammers impersonated bank staff, speaking for 13 minutes until the victim installed an app outside the Play Store
• That app was the SpyNote malware, named after the phone owner to look normal
• It requested Accessibility permissions and then silently installed WindRelay
• The victim was told to tap their card on the phone and enter their PIN — the signal was relayed to the scammer’s phone, which was used at real ATMs or stores
[Insight: Real banks never ask you to tap your card on your phone or enter a PIN in an app. Such calls are clear signs of a scam.]
Kun Long
Author at The Sharing KH