Android NFC Relay Malware (WindRelay) and SpyNote RAT Enable Real‑Time Card Skimming and Loan Fraud
What Happened — A fraudster used a phone‑based social‑engineering call to convince victims to sideload the SpyNote remote‑administration tool, grant it Accessibility Service permissions, and then silently install the WindRelay NFC‑relay malware. Within a single 13‑minute call the attackers took out loans in victims’ names and relayed live NFC card data to complete fraudulent purchases.
Why It Matters for Compliance & Audit Readiness
- The attack exploits weak mobile access controls and the lack of a formal policy governing app sideloading and permission grants—exactly the controls SOC 2 CC6.1 (Logical Access) is designed to protect.
- Continuous evidence of device‑level access‑control enforcement and employee security‑awareness training can demonstrate due diligence during a SOC 2 audit.
Who Is Affected — Financial services (banks, loan processors), payment‑card issuers, and any organization that relies on mobile banking apps for customers.
Recommended Actions
- Map the incident to SOC 2 CC6.1 and CC6.2 (Least‑Privilege Access) and collect evidence of mobile‑device management (MDM) policies, app‑whitelisting, and permission‑review logs.
- Deploy security‑awareness training that covers social‑engineering tactics, especially phone‑based impersonation and the risks of sideloading unknown apps.
Technical Notes — The threat chain combines SpyNote RAT (access via Accessibility Service) with WindRelay, an NFC‑relay tool that captures contactless‑card transaction data in real time. No CVE is cited; the vector is social engineering and permission abuse. Source: BleepingComputer