Listen to this Post

Introduction: When Your Phone Becomes the
Contactless payments were designed around convenience. Tap a card, wait a second, and the transaction is complete. But the same technology that makes payments fast can become dangerous when criminals find a way to separate the card from the place where the payment actually happens.
A newly identified Android malware family known as WindRelay demonstrates exactly how far this threat has evolved. Researchers have found WindRelay being used alongside the established SpyNote remote access trojan, creating a sophisticated fraud chain that combines social engineering, remote device control, NFC interception, and real-time payment relaying.
This is not simply another Android banking trojan stealing credentials in the background. WindRelay attacks the physical payment process itself. The victim can still be holding their legitimate bank card while an attacker, potentially far away, uses the relayed NFC communication to conduct a fraudulent transaction.
Group-IB identified the malware in the wild in late August 2025 and described the campaign as an evolution in Android-based financial fraud. The broader NFC relay ecosystem has also continued to expand, with researchers documenting multiple malware families and criminal services designed to turn compromised Android devices into invisible bridges between payment cards and attacker-controlled terminals.
The Core Threat: WindRelay Relays Live Card Communication
WindRelay is specifically designed to interact with NFC-enabled payment cards and relay their communication in real time.
Instead of merely stealing static card information, the malware participates in the live exchange between a physical payment card and an Android device. The captured communication can then be transmitted to another device controlled by the attacker.
That second device can emulate the
The result is a disturbing separation between the victim and the fraudulent transaction. The victim may be somewhere completely different from the store or cash-out location where the criminal is attempting to use the payment credentials.
Group-IB’s broader research into NFC relay operations has documented this architecture as a major shift in contactless fraud, because the attacker does not necessarily need to physically steal the card or create a traditional magnetic-stripe clone.
SpyNote Adds Remote Control To The Attack
WindRelay becomes substantially more dangerous when paired with SpyNote.
SpyNote is a long-established Android RAT capable of providing attackers with extensive remote access to infected devices. Threat intelligence databases continue to track active SpyNote infrastructure and samples, demonstrating that the malware family remains relevant to the Android threat landscape.
In this campaign, SpyNote provides the remote-control layer while WindRelay performs the specialized NFC relay operation.
That combination gives criminals two very different capabilities inside one attack chain.
One component controls the phone.
The other weaponizes its NFC hardware.
Accessibility Services Become An
A particularly important part of the attack is Android’s Accessibility Service framework.
Accessibility features are legitimate and essential for users who need assistance operating their devices. Unfortunately, criminals frequently attempt to abuse the same capabilities because accessibility permissions can provide powerful control over applications and user-interface interactions.
According to the research described in the original report, SpyNote’s accessibility access can allow the attacker to sideload and activate the NFC component without requiring traditional screen-sharing behavior.
That makes the attack harder for an ordinary victim to recognize.
There may be no obvious remote desktop session. No attacker needs to visibly move the victim’s cursor. Instead, the malicious software can operate through Android’s own accessibility mechanisms.
The Attack Begins With Social Engineering
Technical malware is only one part of the operation.
The first step is often psychological.
Victims can be approached through phishing, smishing, or vishing campaigns. A criminal may impersonate a bank employee, fraud investigator, customer-support representative, or another trusted authority.
The victim is then persuaded to install an application.
The social-engineering component is particularly important because the attackers need the victim to perform an action that security software alone may not prevent.
The malicious APK may be presented as a banking application, security utility, identity-verification tool, or emergency account-protection application.
The victim believes they are cooperating with a legitimate financial institution.
In reality, they are giving the attacker a foothold inside their Android device.
Personalization Makes The Scam More Convincing
One of the most revealing details is that the malicious APK distributed during the phone interaction can be personalized with the victim’s name.
That suggests preparation before the call or message occurs.
A criminal who already knows the
Imagine receiving a call in which the supposed bank employee already knows your name, knows which number they contacted, and confidently explains that suspicious activity has been detected on your account.
The request to install an application may suddenly sound reasonable.
This is why modern mobile fraud cannot be treated solely as a malware problem. It is also an intelligence-gathering and psychological manipulation problem.
The Victim Is Asked To Tap Their Own Card
This is where
The victim may be instructed to place their physical payment card against the infected smartphone.
The criminal can disguise the action as part of an identity-verification process, PIN change, security check, or account-recovery procedure.
The victim is therefore not necessarily handing over their card.
They are voluntarily bringing the card close to a compromised NFC reader.
That subtle distinction is what makes this type of fraud so dangerous.
The physical card remains in the
How The NFC Relay Architecture Works
WindRelay uses two coordinated components.
The first is the reader component installed on the victim’s Android device.
Its job is to communicate with the physical payment card using NFC.
The second is the emulator component running on the attacker’s device.
Its purpose is to reproduce the card-side communication at a payment terminal.
Between these two components sits the
The system can use WebSocket communication to maintain a live connection between the reader and emulator.
EMV APDU commands and responses can then be relayed between the payment terminal and the victim’s physical card.
This is fundamentally different from simply stealing a card number and sending it to a criminal.
The attacker is attempting to preserve the live communication required for the contactless transaction.
Why Real-Time Relaying Matters
Payment cards use dynamic information during transactions, which means traditional concepts of card cloning do not always translate cleanly into the contactless environment.
NFC relay attacks work around this problem by forwarding communication while the transaction is happening.
The attacker does not necessarily need to understand every piece of the payment conversation.
They need to transport the conversation between two locations.
That turns distance into something the criminal can overcome.
A victim can be holding a physical card in one location while an attacker operates a payment terminal somewhere else.
Group-IB’s research describes this broader NFC relay model as a fundamental challenge to the assumption that physical proximity itself provides security for contactless payments.
Ghost Tap Is Becoming A Broader Criminal Ecosystem
The WindRelay operation is part of a much larger evolution commonly associated with Ghost Tap and NFC relay fraud.
Group-IB has documented an expanding ecosystem of Android NFC-enabled malware and criminal services, including dozens of APK variants and underground distribution channels. Its research found more than 54 distinct APK samples in one NFC fraud ecosystem and documented at least $355,000 in illegitimate transactions from a single POS vendor during November 2024 through August 2025.
The important point is that WindRelay is not appearing in isolation.
The criminal economy around NFC relay attacks is becoming increasingly specialized.
Developers can build the malware.
Affiliates can distribute it.
Social engineers can recruit victims.
Mules can perform purchases.
And other criminals can operate payment terminals.
The result resembles a supply chain rather than a traditional one-person cyberattack.
The Geography Of NFC Fraud Is Expanding
NFC relay malware was initially associated with campaigns concentrated in particular European markets, but the technique has increasingly appeared in other countries.
Researchers have documented related NFC relay activity involving countries including Czechia, Brazil, Poland, and Slovakia.
ESET also reported in April 2026 that a new NGate variant was being used against Android users in Brazil and was abusing a legitimate NFC application that had been modified with malicious code. The campaign demonstrated that attackers continue to experiment with different NFC relay implementations rather than relying on a single malware family.
This geographic expansion matters because the underlying technique is not tied to one bank or one country’s payment infrastructure.
Where Android NFC payments and contactless cards are widely used, the basic attack model can potentially be adapted.
WindRelay Creates Two Monetization Channels
The most concerning aspect of the operation is that attackers are not necessarily limited to payment fraud.
The RAT component can potentially support financial-account abuse, credential theft, remote interactions, and fraudulent applications.
The NFC component creates another monetization route through card-present transactions.
This produces a dual-fraud strategy.
One attack can target digital financial services while simultaneously targeting physical payment infrastructure.
Group-IB described this as a combination in which remote access can support fraudulent digital loans while NFC relay capabilities can enable card-present purchases.
The Attack Can Move Faster Than The Victim
Traditional fraud often gives banks time to react.
A suspicious login might trigger an alert.
An unusual transfer might be blocked.
A password reset might generate a notification.
NFC relay attacks introduce a different problem.
The criminal can attempt transactions while the victim is still on the phone with the supposed bank representative.
The social-engineering call becomes a race against the bank’s detection systems.
The longer the victim believes the caller is legitimate, the longer the attacker may have to operate.
Twenty-Three WindRelay Samples Show Continued Development
According to the original research, as many as 23 WindRelay samples were submitted to VirusTotal between November 2025 and July 2026.
The samples reportedly impersonated financial institutions in Czechia, Slovakia, and Slovenia.
That detail is significant because it suggests the operation is not merely an experimental malware project.
The malware is being adapted to a specific regional financial environment.
Brand impersonation can also make malicious applications more convincing during targeted social-engineering campaigns.
Android Security Is Facing A New Class Of Problem
Mobile security has traditionally focused heavily on credentials, malicious overlays, spyware, SMS interception, and banking trojans.
NFC relay malware changes the equation.
The attacker does not necessarily need to steal the card number in a conventional way.
The attacker wants access to the transaction itself.
That means security controls must increasingly understand the relationship between applications, NFC activity, accessibility permissions, device behavior, and financial transactions.
A malicious application requesting NFC access may not be suspicious by itself.
A malicious application requesting NFC access while another unauthorized application has remote-control capabilities is a much stronger signal.
Why Conventional Antivirus May Not Be Enough
Signature-based detection remains useful, but specialized malware can evolve quickly.
Attackers can modify application names, package structures, code, certificates, network infrastructure, and delivery mechanisms.
The more important defensive question becomes behavioral.
What application suddenly requested accessibility privileges?
What application was installed outside the official distribution channel?
Why is a remote-access trojan interacting with NFC functionality?
Why is NFC communication occurring immediately after a suspicious phone call?
Why is an Android device transmitting unusual data to an external WebSocket endpoint?
Security teams need to connect those events.
Banks Have A Role Beyond Transaction Monitoring
Financial institutions cannot rely entirely on customers to identify sophisticated social engineering.
Banks can potentially monitor unusual combinations of signals.
A card transaction from an unexpected location can be one signal.
A sudden account-recovery attempt can be another.
A new-device enrollment can be another.
Fraud detection becomes stronger when these events are analyzed together rather than independently.
The emergence of NFC relay attacks therefore creates pressure for banks to combine device intelligence, transaction intelligence, behavioral analytics, and customer-interaction signals.
Consumers Need To Recognize The Biggest Red Flag
The most important warning is simple.
A legitimate bank should not need you to install an unknown APK during an unsolicited phone call and then place your physical payment card against your phone for an emergency security procedure.
That combination should immediately end the conversation.
Do not continue because the caller knows your name.
Do not trust the caller because they know your bank.
Do not install an application because the caller claims it is required.
And do not tap your card against a phone simply because someone says it is necessary to protect your account.
What Undercode Say:
The Attack Is Bigger Than NFC
WindRelay is important because it demonstrates convergence.
Social Engineering Becomes The Entry Point
The criminal does not begin by breaking Android.
The criminal begins by breaking trust.
SpyNote Provides The Remote-Control Layer
The RAT gives the attacker a foothold inside the victim’s device.
WindRelay Provides The Financial Layer
The NFC component turns that foothold into a payment-relay mechanism.
Accessibility Becomes A Weapon
A legitimate Android accessibility feature can become dangerous when abused by malware.
Personalization Raises The Success Rate
Using a
The Victim Becomes Part Of The Attack
The victim may unknowingly perform the NFC tap themselves.
Physical Card Theft Is Not Required
The card can remain in the
Distance Is No Longer Reliable Protection
The payment terminal can be physically separated from the card.
The Criminal Controls The Other Endpoint
The attacker can use an emulator device to reproduce the payment interaction.
WebSockets Enable Live Communication
A persistent network connection allows the two sides of the relay to communicate.
APDU Relaying Is The Technical Core
The system forwards the commands and responses involved in the contactless transaction.
This Is Not Ordinary Credential Theft
The objective is not merely to learn a password.
The Payment Conversation Is The Target
The malware attempts to transport the live NFC exchange.
Ghost Tap Is Becoming Industrialized
Research has already shown dozens of related NFC malware variants and underground services.
Malware Development Is Becoming Modular
Criminals can combine existing RATs with specialized financial components.
Criminal Roles Can Be Separated
One actor can develop malware while another performs social engineering.
Payment Mules Add Another Layer
Fraudsters can use other individuals or networks to conduct physical transactions.
Financial Fraud Is Becoming Cross-Domain
Digital loans and physical card payments can be attacked in the same campaign.
Android Is A Strategic Target
The
Sideloading Remains A Major Weakness
Malicious APK installation bypasses some of the protections associated with trusted app distribution.
Users Often Trust Authority
A convincing caller can override technical caution.
Caller ID Is Not Proof
Phone numbers and identities can be spoofed or manipulated.
Knowing Personal Information Is Not Proof
Criminals can obtain names and phone numbers before making contact.
A Bank Brand Is Not Proof
Attackers can copy logos, terminology, application names, and scripts.
The Device Can Become The Payment Bridge
That is the defining danger of NFC relay malware.
Detection Must Become Behavioral
Security products need to understand combinations of actions.
Accessibility Plus NFC Deserves Attention
That pairing can be significantly more suspicious than either capability alone.
Remote Control Plus NFC Is Even More Significant
A RAT combined with payment functionality should trigger deeper investigation.
Banks Need Better Device Intelligence
Transaction monitoring alone cannot explain every modern mobile fraud event.
Mobile Security Teams Need NFC Telemetry
NFC-related behavior deserves greater visibility in enterprise and financial-security environments.
Users Need Better Education
Technical controls cannot completely compensate for persuasive social engineering.
Emergency Calls Should Trigger Skepticism
Pressure and urgency are common ingredients in financial scams.
APK Installation During A Call Is A Major Warning
Users should independently contact the institution before installing anything.
NFC Fraud Is Still Evolving
The discovery of new families demonstrates that criminals are actively experimenting.
Brazil Shows The Model Is Spreading
ESET’s 2026 NGate research demonstrates continued NFC relay activity outside the original European clusters.
The Criminal Economy Is Adapting
NFC relay capabilities are increasingly being packaged as usable fraud infrastructure.
The Next Stage Could Be Automation
Large numbers of compromised Android devices could theoretically support coordinated payment activity.
The Real Security Boundary Has Changed
Physical possession of a card no longer automatically guarantees physical control of every transaction involving it.
WindRelay Is A Warning About Convergence
The future of mobile financial malware is likely to combine several capabilities rather than depend on one payload.
The Strongest Defense Is Layered
Secure app distribution, permission controls, behavioral detection, fraud analytics, and user awareness must work together.
Deep Analysis: Detecting Suspicious Android Behavior
Investigate Recently Installed APKs
Security teams investigating a suspected Android infection should begin by identifying applications installed shortly before the fraudulent activity.
adb shell pm list packages -3
Review Installed Application Details
A suspicious package can then be examined for its metadata and installation information.
adb shell dumpsys package
Inspect Accessibility Services
Because accessibility abuse is an important component of many Android RAT campaigns, defenders should examine enabled accessibility services where device-management capabilities permit it.
adb shell settings get secure enabled_accessibility_services
Review Network Connections
Investigators can look for unusual active connections associated with suspicious applications or device behavior.
adb shell dumpsys connectivity
Inspect Running Processes
Unexpected background processes can provide another clue during incident response.
adb shell ps -A
Search Enterprise Telemetry For NFC Activity
Organizations with mobile telemetry should correlate NFC-related events with newly installed applications, accessibility changes, remote-control behavior, and suspicious network activity.
Hunt For WebSocket-Based C2
Because relay systems can maintain persistent communications, defenders should investigate unusual long-lived connections from applications that have no legitimate reason to maintain them.
Correlate Permission Changes
A sudden accessibility permission grant followed by NFC-related behavior should receive additional scrutiny.
Examine Application Provenance
An APK delivered through a phone call, text message, messaging platform, or unknown website should be treated as high risk, especially when it impersonates a financial institution.
Preserve Evidence Before Removing Malware
If an Android device is suspected of being involved in financial fraud, investigators should preserve relevant evidence before resetting the device whenever possible.
Use Known Indicators Carefully
Security teams should avoid treating one filename or package name as a complete detection strategy.
Modern Android malware frequently changes identifiers.
Build Behavioral Detections
A stronger detection might combine:
New APK installation
+
Accessibility privilege
+
NFC access
+
Remote-control capability
+
External C2 connection
=
High-risk mobile fraud behavior
Protect The Payment Layer
Banks and payment providers should investigate whether transaction risk models can detect impossible or unusual relationships between device location, card location, transaction location, and device identity.
Educate Customers Before Fraud Happens
The most effective intervention may occur before installation.
Customers should know that unsolicited callers requesting APK installation or unusual NFC card interactions are not following normal banking security procedures.
Accuracy Review
✅ Confirmed: NFC relay malware is a documented Android threat, and Group-IB has publicly documented Ghost Tap-style malware that relays NFC communications between victims and attacker-controlled devices.
✅ Confirmed: SpyNote is a real Android RAT family that remains represented in current threat-intelligence telemetry.
⚠️ Context: The specific WindRelay details, including the 23 samples and its exact SpyNote integration, come from the Group-IB research described in the source article; the broader NFC-relay threat is independently supported by Group-IB and ESET research.
Prediction
(+1) NFC Relay Fraud Will Become More Modular
Attackers are likely to continue combining established Android RATs with specialized NFC components instead of developing every capability inside one malware family.
(+1) Criminals Will Target More Countries
The appearance of related campaigns in Brazil and other regions suggests that NFC relay fraud is moving beyond a narrow geographic cluster.
(+1) Social Engineering Will Remain Central
Technical defenses can be bypassed when attackers persuade victims to install software and physically interact with their own payment cards.
(+1) Financial Malware Will Converge
Future campaigns may combine banking trojans, remote-access capabilities, identity theft, NFC relay, and fraudulent lending into a single coordinated operation.
(-1) Simple Signature Detection Will Become Less Effective
Malware developers can change application packaging and infrastructure faster than traditional signatures can always adapt.
(-1) Physical Card Possession Will Not Guarantee Safety
As relay technology improves, simply keeping the physical card in your wallet may not be sufficient protection against every form of contactless fraud.
Final Perspective: The Phone Is Becoming Part Of The Payment Attack Surface
WindRelay represents a deeper change in mobile financial crime.
The attacker is no longer necessarily trying to steal the card.
They may not even need to steal the card number.
Instead, they can attempt to turn the
That is what makes the combination of SpyNote and WindRelay so concerning.
The RAT controls the phone.
Social engineering controls the
NFC provides access to the payment channel.
The relay infrastructure connects the two locations.
And the criminal gets a pathway from a compromised Android device to the physical world.
The broader research already shows that NFC relay malware is developing rapidly, with multiple families, underground services, regional campaigns, and increasingly sophisticated delivery methods.
The lesson for consumers is brutally simple: never install an APK because an unsolicited caller tells you it is necessary to protect your bank account, and never tap your payment card against an unfamiliar phone as part of an emergency security procedure.
The lesson for security teams is even more important.
Mobile security can no longer stop at passwords, SMS messages, and banking applications.
The NFC layer itself has become part of the financial attack surface.
▶️ Related Video (74% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




