A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme.

The purpose-built malware, according to Group-IB, is designed to capture live card data via NFC and transmit it to fraudsters in real time. It was first detected in the wild in late August 2025.

"SpyNote's Accessibility Service access lets the fraudster sideload and activate the NFC app silently, with no screen sharing ever triggered," researchers Alexander Grabko, Konstantinos Angelopoulos, Pavlos Gaitanis, and Bruno Bijelić said

These attacks typically work by luring prospective targets via phishing, smishing, or vishing scams into sideloading a malicious app. Once installed, the threat actor abuses SpyNote's remote access to install the NFC relay malware without any further user interaction.

To lend credibility to the scheme, the APK file distributed during the phone call is personalized with the victim's name, indicating the delivery process is tailored per target. This points to a pre-call reconnaissance phase where the threat actor harvests the victim's name and phone number to make the social engineering pretext more persuasive.

Subsequently, the victim is socially engineered into tapping their physical payment card against their own infected phone under the pretext of identity verification or changing their PIN and verifying their banking card following a purported compromise of their account.

In doing so, it turns the victim's device into a payment proxy without their awareness and a live bridge for contactless payment fraud, allowing the malware to intercept and read the card's radio signals using NFC and stream them in real-time to a fraudster's separate device elsewhere.

WindRelay is no different in that it incorporates two components that work in sync with each other -

  • A reader component installed on the victim's device, which interfaces with the physical payment card via NFC
  • An emulator component installed on the threat actor's device, which emulates the card at a payment terminal

These two components interact through a shared command-and-control (C2) infrastructure over WebSocket, relaying EMV APDU commands and responses between the terminal and the victim's card in real-time.

The development comes as NFC relay malware targeting Android has proliferated, expanding beyond the Czech Republic to Brazil, Poland, and Slovakia over the past year.

The primary advantage of this technique, also called Ghost Tap, is that it allows cybercriminals to stay anonymous and perform cashouts at a larger scale as capturing the NFC data of banking customers makes it possible to mimic their bank card on their own device and use it for cash withdrawals or to make payments.

"Theoretically, they could have whole farms of Android phones loaded with compromised card data making automated fraudulent transactions," ESET noted in a report published last year.

The latest findings from Group-IB demonstrate a potent combination of NFC relay and RAT capabilities, granting the attacker more ways to extract data, retain persistent access, and conduct financial fraud.

As many as 23 WindRelay samples have been uploaded to VirusTotal between November 2025 and July 2026, impersonating financial institutions in Czechia, Slovakia, and Slovenia.

The Singapore-headquartered cybersecurity company said this represents a new evolution of Android malware and a dual monetization strategy within a single scheme, where "RAT-driven remote access can be used to take out a digital loan, while the NFC malware enables physical, card-present purchases."

"This case shows that modern fraud rarely relies on one technique," the researchers added. "Here, the fraudster combined three capabilities in a single session — a live social engineering call, a personalized RAT for remote device control, and an NFC relay malware for physical cashout."

"The fraudster also used these capabilities to hit two separate payout channels — a digital loan and card-present purchases — before the bank or victim could react."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.