A new Android malware chain is turning NFC-equipped smartphones into live card relays for contactless payment fraud, in attacks that play out while victims stay on the phone with impostor bank staff.[1][2][3]
Researchers at Group-IB have identified the previously unseen NFC relay malware family WindRelay being deployed alongside the SpyNote remote access trojan (RAT) to hijack card taps and stream transaction data to criminal devices in real time.[2][3][6]
In one documented case, the operators converted a 13-minute vishing call into a loan in the victim’s name and subsequent card fraud without ever touching the card themselves.[2][4][5]
The attack typically begins with a highly scripted phone call in which fraudsters pose as bank employees, warning of urgent security issues and persuading targets to install a fake banking app that is in fact SpyNote.[2][3][4]
Once SpyNote is sideloaded, it gives the attacker remote control over the Android device, enabling them to silently install WindRelay, tamper with legitimate banking apps, and manage the device while the victim remains on the line.[2][3][6]
Group-IB reports campaigns targeting users in Europe, where attackers remotely open banking apps to initiate loans before instructing victims to tap their physical payment cards on the compromised phone and enter the PIN when prompted.[2][4][6]
WindRelay’s role is to abuse Near Field Communication (NFC) by behaving like a point-of-sale terminal on the phone, talking directly to the card’s chip when it is tapped against the handset.[2][3][13]
Instead of cloning static NFC identifiers, the malware captures the live EMV application protocol data unit exchange and relays it over the internet to an attacker-controlled device positioned at a legitimate payment terminal or ATM.[2][3][6]
Because modern contactless cards generate dynamic, per-transaction cryptograms, the relay must preserve precise timing, placing WindRelay firmly in the growing ghost-tap style of NFC relay fraud.[2][8][13]
Unlike traditional banking Trojans that exploit software vulnerabilities, the WindRelay–SpyNote chain primarily abuses legitimate platform features such as NFC, Android sideloading and Accessibility permissions combined with social engineering over the phone.[2][3][11]
There are currently no public CVE identifiers or vendor security advisories tied specifically to WindRelay, underscoring that the core problem is user coercion rather than a patchable flaw.[1][2][3]
The live call doubles as a control channel, allowing operators to walk victims through app installation, card tapping and PIN entry in carefully timed steps that make it harder for targets to step back and verify the story.[2][4][12]
The campaign fits into a broader rise in NFC relay attacks and remote tap-to-pay fraud, with earlier tools such as NGate, SuperCard X and RelayNFC showing that criminal groups are actively investing in relay infrastructure for carding operations.[2][10][15]
In these schemes, compromised phones or wallets forward NFC frames to distant devices at real payment terminals, letting mules withdraw cash or perform in-store purchases that appear legitimate to acquiring banks.[8][11][14]
Researchers warn that the combination of instant loans, real-time card relays and mules at terminals can compress the entire fraud cycle into a single call, leaving banks and victims little time to react.[2][5][10]
Defenders advise treating unsolicited calls or texts about urgent banking issues as suspect, refusing to install apps from links sent during a call, and independently contacting the bank using official numbers published on cards or statements.[2][3][14]
Android users can reduce exposure by avoiding sideloaded apps, scrutinizing Accessibility and device-control permissions, keeping mobile operating systems and banking apps updated, and running reputable mobile security tools that detect SpyNote, WindRelay and related NFC relay malware families.[2][3][5]
Most importantly, cardholders should never tap a payment card on their phone or share PINs at the direction of a caller, since those actions are precisely what allow WindRelay operators to turn a personal device into a remote card skimmer.[2][4][14]
References
- WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud
- A New Malware Combo Behind a Growing Fraud Scheme – Group-IB
- Android malware combo takes out loans and relays victims’ credit …
- Smooth-talking fraudsters clone contactless cards, authorize …
- CyberHappenings — Sourced Cybersecurity Happenings and Timelines
- Group-IB’s Post – LinkedIn
- Ghost-Tap: How Hackers Exploit NFC and Mobile Payments
- Android malware targets mobile payment users through …
- NFC Payment Fraud in 2026: How Relay Attacks Steal Money
- SpyNote Android Spyware Strikes Financial Institutions
- What Is NFC relay attack? Definition & Examples
- Direct and reverse NFC relay attacks being used to steal …
- How to guard against NFC carding theft | Kaspersky official blog
