A new malware strain, WindRelay, is being used in conjunction with the SpyNote remote access trojan (RAT) in a fraud scheme, where criminals impersonate bank employees to manipulate victims during a phone call. The fraudster instructs the victim to install an app that appears to be tailored to them, using their name to enhance believability.
The WindRelay malware captures NFC card data live when the victim uses their card, allowing the fraudster to relay this data to a legitimate terminal and even take out loans using the victim's banking app. Group-IB has issued guidelines to aid in avoiding such scams, emphasizing awareness of app installations from unofficial sources during phone interactions.