Cybercrime
WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud
Cyber RTAugust 16, 20263 min read

WindRelay, a new Android NFC relay malware, is used with the SpyNote RAT in a contactless payment fraud scheme. Discovered in August 2025, it captures card data via NFC and transmits it to fraudsters. The malware exploits SpyNote's remote access to silently install itself. Victims are tricked into using their infected phones as payment proxies, enabling real-time data interception. WindRelay's dual components—reader and emulator—facilitate fraud by mimicking bank cards. This technique, expanding globally, allows anonymous, large-scale fraudulent transactions. Group-IB highlights its dual monetization strategy, combining RAT-driven remote access and
The article discusses the emergence of a new Android NFC relay malware family called WindRelay, which is being used alongside a known remote access trojan (RAT) named SpyNote in a sophisticated contactless payment fraud scheme. This malware is specifically designed to capture live card data via NFC and transmit it to fraudsters in real-time. The malware was first detected in late August 2025, and its deployment marks a significant advancement in the tactics used by cybercriminals to exploit contactless payment systems.
WindRelay operates by leveraging SpyNote's Accessibility Service access, which allows fraudsters to silently sideload and activate the NFC app without triggering any screen sharing. This method is part of a broader attack strategy where victims are lured into installing a malicious app through phishing, smishing, or vishing scams. Once the app is installed, SpyNote's remote access capabilities are used to install the NFC relay malware without requiring further user interaction, making the attack seamless and difficult to detect.
To enhance the credibility of the scam, the APK file distributed during the attack is personalized with the victim's name. This indicates that the attackers conduct a pre-call reconnaissance phase to gather the victim's personal information, such as their name and phone number, to make the social engineering tactics more convincing. Victims are then manipulated into tapping their physical payment card against their infected phone under false pretenses, such as verifying their identity or changing their PIN.
The infected device effectively becomes a payment proxy without the victim's knowledge, serving as a live bridge for contactless payment fraud. The malware intercepts and reads the card's radio signals using NFC, streaming them in real-time to a fraudster's device elsewhere. WindRelay consists of two components: a reader component on the victim's device that interfaces with the card via NFC, and an emulator component on the fraudster's device that emulates the card at a payment terminal.
These components interact through a shared command-and-control infrastructure over WebSocket, relaying EMV APDU commands and responses between the terminal and the victim's card in real-time. This technique, known as Ghost Tap, allows cybercriminals to remain anonymous and perform large-scale cashouts by capturing NFC data and using it to mimic bank cards for fraudulent transactions. The proliferation of NFC relay malware has expanded beyond the Czech Republic to countries like Brazil, Poland, and Slovakia.
The article highlights that the combination of NFC relay and RAT capabilities in WindRelay provides attackers with multiple avenues to extract data, maintain persistent access, and conduct financial fraud. Group-IB's findings reveal that 23 WindRelay samples have been uploaded to VirusTotal, impersonating financial institutions in Czechia, Slovakia, and Slovenia. This development signifies a new evolution in Android malware, where a dual monetization strategy is employed within a single scheme.
The fraudsters in this case combine three capabilities in a single session: a live social engineering call, a personalized RAT for remote device control, and NFC relay malware for physical cashout. This approach enables them to exploit two separate payout channels—digital loans and card-present purchases—before the bank or victim can respond. The article underscores the complexity of modern fraud schemes, which often rely on multiple techniques to maximize their effectiveness and evade detection.


