← Back to Daily Briefing (#USCYBERCOM)

Android attackers are utilizing a dual-payload chain, combining the SpyNote Remote Access Trojan (RAT) with the WindRelay module to perform real-time Near Field Communication (NFC) relay attacks. Initial access is achieved via vishing and the sideloading of malicious APKs. Following deployment, SpyNote provides remote administrative control to install WindRelay, which intercepts contactless payment credentials through Host Card Emulation (HCE) manipulation or NFC stack hooking. These credentials are relayed via Command and Control (C2) infrastructure to remote attackers, enabling unauthorized physical transactions at POS terminals and ATMs. This chain bypasses proximity requirements and facilitates multi-factor authentication (MFA) bypass through concurrent SMS interception and Accessibility Service abuse.

  • Initial Access: Social Engineering and Deployment

    • Execution of vishing (voice phishing) campaigns where attackers impersonate financial institution employees to induce urgency.
    • Distribution of malicious, personalized APKs designed to mimic legitimate banking or system utility applications.
    • Exploitation of user trust to bypass Google Play Store security via manual sideloading of third-party applications.
  • Technical Execution: NFC Interception and Relay

    • Deployment of the WindRelay module as a secondary payload facilitated by SpyNote's remote administration capabilities.
    • Exploitation of the Android NFC stack and Host Card Emulation (HCE) to intercept live contactless payment data.
    • Real-time relaying of intercepted cryptographic credentials via internet-based Command and Control (C2) infrastructure.
    • Successful bypass of the physical proximity requirement inherent to standard NFC-based security protocols.
  • Payload Capabilities and Data Exfiltration

    • Manipulation of Android Accessibility Services to gain comprehensive device control and intercept user interactions.
    • Concurrent execution of SMS interception to bypass multi-factor authentication (MFA) during unauthorized banking sessions.
    • Integration of secondary exfiltration modules, including keylogging, screen capturing, and device administrator privilege abuse.
  • Financial Impact: "Ghost-Tap" Fraud and Beyond

    • Facilitation of "Ghost-Tap" style fraud, enabling remote, in-person cash-outs at physical retail terminals and ATMs.
    • Execution of rapid, unauthorized fund transfers and fraudulent loan applications using stolen identity data.
    • High-efficiency fraud targeting high-value demographics through highly personalized malware metadata and UI elements.
  • Detection and Mitigation Strategies

    • Deployment of Mobile Threat Defense (MTD) solutions capable of identifying HCE hijacking and NFC stack manipulation.
    • Monitoring for anomalous permission requests, specifically those targeting Accessibility Services and Device Administrator privileges.
    • Strengthening user awareness training regarding the risks of sideloading third-party APKs and responding to unsolicited technical support calls.

Related posts

  1. techjacksolutions.com — WindRelay + SpyNote Android Malware Duo Enables Real-Time NFC Payment Card Relay and Device Takeover
  2. blackhatnews.tokyo — WindRelayとSpyNote RATの組み合わせ、Androidを銀行詐欺用NFCカードリレーに変える
  3. eSecurity Planet — New Android Malware Chain Turns Bank Support Scams Into NFC Card Fraud
  4. bleepingcomputer.com — Android malware combo takes out loans and relays victims' credit cards
  5. helpnetsecurity.com — New Android malware relays bank cards to fraudsters while victims still hold them
  6. Pcrisk
  7. Blog
  8. Androidheadlines
  9. Malwarebytes
  10. Group-ib
  11. Thehackernews
  12. Infosecurity-magazine
  13. Daily
  14. Sisa
  15. Cleafy
  16. Techradar
  17. Phishingtackle
  18. Reddit
  19. Group-ib
  20. Group-ib
  21. Group-ib
  22. Mallory
  23. Facebook
  24. Nerdpress
  25. Malwarebytes
  26. Malwarebytes
  27. Malwarebytes
  28. Malwarebytes
  29. Infosecurity-magazine
  30. Infosecurity-magazine
  31. Infosecurity-magazine
  32. Infosecurity-magazine
  33. Mallory
  34. Infosecurity-magazine

LINK COPIED TO CLIPBOARD