logo

Attackers Use Vishing Attacks to Distribute New Android Malware

ID: 99749398-b8ce-52c0-93ff-e7a32643cf2d

STIX ID: report--99749398-b8ce-52c0-93ff-e7a32643cf2d

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: KnowBe4 Team

...
...

Researchers at Group-IB detail "WindRelay", an Android malware campaign that combines a RAT (Spynote-like) and an NFC relay to enable phone-call social engineering fraud: attackers call victims posing as bank staff, guide them to install a RAT, which is then used to silently install NFC relay malware to capture card taps and PINs and execute fraudulent transactions and loans. Group-IB observed the attackers complete an entire theft in as little as 13 minutes, streaming card data to a fake terminal while the victim remained on the call.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.