New Android Malware 'WindRelay' Distributed via Vishing Attacks, Group-IB Reports
Cybersecurity researchers at Group-IB have identified a new Android malware named 'WindRelay' being distributed through phone-based social engineering attacks, specifically vishing. Attackers impersonate bank employees and instruct victims to install a malicious application. In one documented instance, the entire attack, from initial contact to the installation of a Remote Access Trojan (RAT) and subsequent fraudulent loan acquisition, was completed within thirteen minutes. The scammers guided the victim to install the first malicious app, labeled with the victim's name. Subsequently, using the RAT's remote access capabilities, a second app, an NFC relay malware, was installed without further victim interaction. The attackers then used this access to take out a loan in the victim's name and stream card data to a fake merchant terminal, with the victim approving transactions by entering their PIN as instructed, all while remaining on the call with the fraudster.