CyberSecurityBoardThreat Intel · CVEs · Products
Malware

WindRelay Android Malware Turns Phones into NFC Relays for Payment Fraud

August 13, 2026

Cybersecurity researchers at Group-IB have uncovered a new Android malware family called WindRelay that turns victims’ smartphones into NFC relays for contactless payment fraud. The malware is deployed alongside the known remote access trojan (RAT) SpyNote, enabling fraudsters to silently install the NFC relay app and capture live card data in real time.

First detected in late August 2025, WindRelay attacks typically begin with phishing, smishing, or vishing campaigns that trick victims into sideloading a malicious app. The threat actor uses SpyNote’s Accessibility Service access to install the NFC relay malware without triggering screen sharing. The APK is personalized with the victim’s name, indicating pre-call reconnaissance to make social engineering more convincing.

Victims are then socially engineered into tapping their physical payment card against their own infected phone under the pretext of identity verification or PIN change. This turns the device into a payment proxy, intercepting NFC radio signals and streaming them to a fraudster’s device elsewhere. WindRelay consists of two components: a reader on the victim’s device and an emulator on the attacker’s device, communicating via WebSocket through a shared command-and-control infrastructure.

This technique, also known as Ghost Tap, allows cybercriminals to remain anonymous and perform cashouts at scale. Group-IB identified 23 WindRelay samples on VirusTotal between November 2025 and July 2026, impersonating financial institutions in Czechia, Slovakia, and Slovenia. The malware represents a dual monetization strategy, combining RAT-driven remote access for digital loans and NFC relay for physical card-present purchases.

Malware: WindRelay, SpyNote

Companies: Group-IB, ESET