Hacking

Android NFC Relay Malware WindRelay Enables Payment Fraud

Published  ·  10 min read

A previously unseen Android near field communication relay malware family has been discovered in the wild. The malware, dubbed WindRelay, is being deployed in conjunction with a known remote access trojan called SpyNote as part of an elaborate contactless payment fraud scheme.

The Android NFC relay malware WindRelay is designed to capture live card data via NFC and transmit it to fraudsters in real time. The malware was detected in late August 2025 by Group-IB, and it is currently becoming a serious threat to multiple countries.

Now, let me give an insight into the workings of the Android NFC relay malware known as WindRelay, and what Android users need to know to protect themselves.

Important Information on WindRelay

  • WindRelay is an NFC relay malware targeting Android
  • WindRelay operates in tandem with SpyNote RAT
  • Can steal card details through NFC real-time
  • Transmits the data to fraudsters via WebSocket C2
  • Helps in committing contactless payment fraud and cashouts
  • First detected in August 2025
  • Impersonates financial institutions across multiple countries

The Growing Threat of NFC Relay Malware

NFC relay malware targeting Android has proliferated significantly over the past year. What began as a localized threat in the Czech Republic has now expanded to Brazil, Poland, and Slovakia. This shows that the motivation for cyber criminals in using contactless payment fraud is becoming more common.

The Android NFC relay malware WindRelay represents an evolution of this threat. Unlike earlier variants that required physical proximity to the victim, WindRelay enables remote relay attacks through a sophisticated combination of social engineering, remote access trojans, and real-time NFC data streaming.

The primary advantage of this technique, also called Ghost Tap, is that it allows cybercriminals to stay anonymous and perform cashouts at a larger scale. Capturing the NFC data of banking customers makes it possible to mimic their bank cards on the fraudster's own device and use them for cash withdrawals or to make payments at physical terminals.

How the Attack Works

The Android NFC relay malware WindRelay attack follows a multi-stage process that combines social engineering, remote access, and NFC relay technology.

Step 1: Initial Contact

The attackers employ phishing, smishing, and vishing as ways to persuade prospective victims into installing the malicious app by means of sideloading. The APK file that gets delivered as part of the phone call gets customized using the victim’s name, thus suggesting that the delivery phase is customized for each particular victim.

In all likelihood, it is preceded by a reconnaissance phase where the threat actor harvests the victim's name and phone number to make the social engineering pretext more persuasive.

Step 2: SpyNote Installation

SpyNote RAT is installed on the victim's device. The malware abuses Accessibility Service access, which lets the fraudster sideload and activate the NFC app silently, with no screen sharing ever triggered. Following the installation process, the threat actor can use SpyNote’s remote access capability to install the NFC relay malware without needing further user interaction.

Step 3: Installation of NFC Malware

With the help of the SpyNote remote access capabilities, the attacker installs WindRelay malware silently on the victim's system. The user will have no idea that malware has been installed on their system because this is all done quietly in the background without giving any alerts at all.

Step 4: Social Engineering

The victim is socially engineered into tapping their physical payment card against their own infected phone. The pretext is normally one of identity authentication, PIN change, or validation of their bank card after some kind of alleged compromise of their account. The victim believes they are taking a legitimate security action, unaware that they are unknowingly participating in their own fraud.

Step 5: Card Data Capture

The victim taps their physical payment card against the infected phone. The Android NFC relay malware WindRelay intercepts and reads the card's radio signals using NFC and streams them in real-time to a fraudster's separate device elsewhere. This turns the victim's device into a payment proxy without their awareness, creating a live bridge for contactless payment fraud.

WindRelay's Two Components

The WindRelay Android NFC relay malware is made up of two components which function simultaneously in order to facilitate the relay attack.

Readers Component:

The readers component  is installed on the victim's device. This component cooperates with the physical credit card using the NFC technology in order to pass EMV APDU commands from the card and terminal.

Emulator Component:

The emulator component is present in the device used by the threat actor. It serves as a simulated card at the payment terminal, and reproduces the information of the stolen card to perform the fraudulent transaction.

Communication between these two components:

These two components communicate through command and control via WebSocket. This provides a relay of EMV APDU command and responses between the payment terminal and the card of the victim in real time, creating a seamless relay that fraudsters can use for cashouts.

The Ghost Tap Technique

The Android NFC relay malware WindRelay uses the Ghost Tap technique to enable fraudulent transactions.

What Is Ghost Tap?

The Ghost Tap technique involves relaying the information stored on cards in real time using NFC. The fraudsters could emulate the bank cards using their own devices to withdraw money or pay for something at the terminal.

Advantages for Attackers:

The technique allows cybercriminals to stay anonymous while performing cashouts at a larger scale. Capturing the NFC data of banking customers makes it possible to mimic their bank cards on the fraudster's own device.

Automated Fraud:

ESET noted in a report published last year: "Theoretically, they could have whole farms of Android phones loaded with compromised card data making automated fraudulent transactions."

This highlights the scalability of the threat.

  • The Spread of WindRelay
  • The Android NFC relay malware WindRelay is detected in various countries.
  • Timeline for Detection:
  • Late August 2025 – Discovered in the wild
  • November 2025 to July 2026 – 23 samples uploaded to VirusTotal

Countries Affected by the Malware:

  • Czech Republic
  • Brazil
  • Poland
  • Slovakia
  • Slovenia

Institutions Impersonated by the Malware:

This particular malware imitates financial institutions in Czech Republic, Slovakia, and Slovenia. These APKs have been created in such a way that they resemble real banking applications, making them more convincing to victims.

The Dual Monetization Strategy

The Android NFC relay malware WindRelay enables a dual monetization strategy within a single scheme.

Channel 1: Digital Loans

RAT-driven remote access can be used to take out a digital loan in the victim's name. Through the capability provided by SpyNote, the attacker gains access to the banking application and applies for loans.

Channel 2: Purchases Using Physical Cards

Using NFC relay malware, physical purchases using cards are possible. The attacker then manages to get money withdrawn or make purchases through the terminals physically.

Combination Approach:

The Group-IB researchers noted: "RAT-driven remote access can be used to take out a digital loan, while the NFC malware enables physical, card-present purchases." This creates two separate payout channels for the fraudster.

The Researchers' Analysis

The Group-IB researchers highlighted the sophistication of the Android NFC relay malware WindRelay.

Key Observations:

"Modern fraud rarely relies on one technique," the researchers said. "Here, the fraudster combined three capabilities in a single session — a live social engineering call, a personalized RAT for remote device control, and an NFC relay malware for physical cashout."

The Result:

"The fraudster also used these capabilities to hit two separate payout channels — a digital loan and card-present purchases — before the bank or victim could react."

The researchers, Alexander Grabko, Konstantinos Angelopoulos, Pavlos Gaitanis, and Bruno Bijelić, noted that this represents a new evolution of Android malware and a dual monetization strategy within a single scheme.

What Users Should Do

The Android NFC relay malware WindRelay requires awareness and caution from Android users.

Protection Measures:

  • Install applications from the Google Play Store only
  • Avoid downloading APK files from unauthorized sources
  • Be suspicious of any calls regarding your bank
  • Do not use the card in contact with the phone
  • Confirm messages from the bank through an authorized channel
  • Enable Google Play Protect on the phone

Detection:

  • Check for unknown applications on your device
  • Search for applications with accessibility permissions
  • Detect any abnormal use of NFC
  • Detect any unexpected banking notifications

In Case of Compromise:

  • Alert your bank
  • Notify them about any unauthorized transactions
  • Reset your phone to factory settings
  • Update all banking passwords
  • Monitor your accounts for suspicious activity

The Evolution of Android NFC Malware

The Android NFC relay malware WindRelay represents a significant evolution of Android malware.

Threat on the Rise:

NFC relay malware is becoming prevalent this year. The specific malware mentioned is known to propagate from the Czech Republic to other locations including Brazil, Poland, and Slovakia. This is evidenced by 23 cases of this malware found by VirusTotal from November 2025 to July 2026.

Combination:

The capability to employ RAT in combination with NFC relay attack has started getting exploited. This is creating new ways to collect information, sustain the presence, and perpetrate the frauds. Double revenue business model makes the attack more lucrative for cybercriminals.

Implications of This:

The Android malware NFC relay known as WindRelay demonstrates how advanced attacks targeting mobile banking are today. In order to protect oneself from such attacks, it is very important that one stays vigilant and follows security practices.

Conclusion

WindRelay is an extremely sophisticated type of malware that allows for contactless payment card scams. In combination with SpyNote RAT, WindRelay is able to transfer data from the victim’s card to the fraudster’s payment terminal in real time.

Key points to remember:

  • WindRelay captures live card data via NFC
  • Works with SpyNote RAT for remote access
  • Enables two monetization channels: digital loans and card-present purchases
  • Spread across 5 countries
  • 23 samples detected between November 2025 and July 2026
  • Combines social engineering, RAT, and NFC relay

Android users should only install apps from trusted sources. Be suspicious of unsolicited calls about bank accounts. Never tap your card on a phone under instruction. Report any unauthorized transactions immediately.

The Android NFC relay malware WindRelay is a reminder that modern fraud rarely relies on one technique. Stay vigilant and protect your financial information.

FAQ Section

What is the Android NFC relay malware WindRelay?

WindRelay is an Android malware that captures live card data via NFC and relays it to fraudsters in real time. It works with the SpyNote RAT to enable contactless payment fraud.

How does the attack work?

The attacker employs techniques such as phishing or vishing to trick the victim into sideloading SpyNote RAT. SpyNote then covertly installs WindRelay. The victims are socially engineered to wave their card on the compromised phone in order to harvest the details of their card.

What is the Ghost Tap attack?

The Ghost Tap is the NFC relay attack, which allows harvesting and relaying of card details in real time. This attack will allow mimicking of bank cards to withdraw money.

Which countries are affected?

WindRelay has been detected in the Czech Republic, Brazil, Poland, Slovakia, and Slovenia. It impersonates financial institutions in Czechia, Slovakia, and Slovenia.

What should users do?

Only install apps from the Google Play Store. Be suspicious of unsolicited bank calls. Never tap your card on a phone under instruction. Report any unauthorized transactions immediately.

Source: The Hacker News

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067