WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud Ravie Lakshmanan Aug 13, 2026 Malware / Mobile Security A previously unseen Android near field communication ( NFC ) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme. The purpose-built malware, according to Group-IB, is designed to capture live card data via NFC and transmit it to fraudsters in real time. It was first detected in the wild in late August 2025. "SpyNote's Accessibility Service access lets the fraudster sideload and activate the NFC app silently, with no screen sharing ever triggered," researchers Alexander Grabko, Konstantinos Angelopoulos, Pavlos Gaitanis, and Bruno Bijelić said . These attacks typically work by luring prospective targets via phishing, smishing, or vishing scams into sideloading a malicious app. Once installed, the threat actor abuses SpyNote's remote access to install the NFC relay malware without any further user interaction. To lend credibility to the scheme, the APK file distributed during the phone call is personalized with the victim's name, indicating the delivery process is tailored per target. This points to a pre-call reconnaissance phase where the threat actor harvests the victim's name and phone number to make the social engineering pretext more persuasive. Subsequently, the victim is socially engineered into tapping their physical payment card against their own infected phone under the pretext of identity verification or changing their PIN and verifying their banking card following a purported compromise of their account. In doing so, it turns the victim's device into a payment proxy without their awareness and a live bridge for contactless payment fraud, allowing the malware to intercept and read the card's radio signals using NFC and stream them in real-time to a fraudster's separate device elsewhere. WindRelay is no different in that it incorporates two components that work in sync with each other - A reader component installed on the victim's device, which interfaces with the physical payment card via NFC An emulator component installed on the threat actor's device, which emulates the card at a payment terminal These two components interact through a shared command-and-control (C2) infrastructure over WebSocket, relaying EMV APDU commands and responses between the terminal and the victim's card in real-time. The development comes as NFC relay malware targeting Android has proliferated, expanding beyond the Czech Republic to Brazil, Poland, and Slovakia over the past year. The primary advantage of this technique, also called Ghost Tap, is that it allows cybercriminals to stay anonymous and perform cashouts at a larger scale as capturing the NFC data of banking customers makes it possible to mimic their bank card on their own device and use it for cash withdrawals or to make payments. "Theoretically, they could have whole farms of Android phones loaded with compromised card data making automated fraudulent transactions," ESET noted in a report published last year. The latest findings from Group-IB demonstrate a potent combination of NFC relay and RAT capabilities, granting the attacker more ways to extract data, retain persistent access, and conduct financial fraud. As many as 23 WindRelay samples have been uploaded to VirusTotal between November 2025 and July 2026, impersonating financial institutions in Czechia, Slovakia, and Slovenia. The Singapore-headquartered cybersecurity company said this represents a new evolution of Android malware and a dual monetization strategy within a single scheme, where "RAT-driven remote access can be used to take out a digital loan, while the NFC malware enables physical, card-present purchases." "This case shows that modern fraud rarely relies on one technique," the researchers added. "Here, the fraudster combined three capabilities in a single session — a live social engineering call, a personalized RAT for remote device control, and an NFC relay malware for physical cashout." "The fraudster also used these capabilities to hit two separate payout channels — a digital loan and card-present purchases — before the bank or victim could react." Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share Share on Facebook Share on Twitter Share on Linkedin Share on Reddit Share on Hacker News Share on Email Share on WhatsApp Share on Facebook Messenger Share on Telegram SHARE Android security , banking security , Cybercrime , Financial Fraud , Malware , mobile security , Payment Security , Phishing , Remote Access Trojan , Social Engineering ⚡ Top Stories This Week Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ⭐ Featured Resources See How to Stop the Browser-Based Attacks Your Existing Stack Misses [Book a Live Demo] [Webinar] See Where Claude Fits in the SOC and Where It Falls Short at Scale Defend Against One-Click AI Memory Poisoning — Download the Cheat Sheet Benchmark Your Defenses Against 338M+ Attack Simulations — Download the Blue Report 2026