WindRelay Turns Android Phones Into Invisible Payment Bridges, Bringing NFC Fraud Into a New and Dangerous Era + Video

Listen to this Post

Featured Image

Introduction: When Your Phone Becomes the

Contactless payments were designed around convenience. Tap a card, wait a second, and the transaction is complete. But the same technology that makes payments fast can become dangerous when criminals find a way to separate the card from the place where the payment actually happens.

A newly identified Android malware family known as WindRelay demonstrates exactly how far this threat has evolved. Researchers have found WindRelay being used alongside the established SpyNote remote access trojan, creating a sophisticated fraud chain that combines social engineering, remote device control, NFC interception, and real-time payment relaying.

This is not simply another Android banking trojan stealing credentials in the background. WindRelay attacks the physical payment process itself. The victim can still be holding their legitimate bank card while an attacker, potentially far away, uses the relayed NFC communication to conduct a fraudulent transaction.

Group-IB identified the malware in the wild in late August 2025 and described the campaign as an evolution in Android-based financial fraud. The broader NFC relay ecosystem has also continued to expand, with researchers documenting multiple malware families and criminal services designed to turn compromised Android devices into invisible bridges between payment cards and attacker-controlled terminals.

The Core Threat: WindRelay Relays Live Card Communication

WindRelay is specifically designed to interact with NFC-enabled payment cards and relay their communication in real time.

Instead of merely stealing static card information, the malware participates in the live exchange between a physical payment card and an Android device. The captured communication can then be transmitted to another device controlled by the attacker.

That second device can emulate the

The result is a disturbing separation between the victim and the fraudulent transaction. The victim may be somewhere completely different from the store or cash-out location where the criminal is attempting to use the payment credentials.

Group-IB’s broader research into NFC relay operations has documented this architecture as a major shift in contactless fraud, because the attacker does not necessarily need to physically steal the card or create a traditional magnetic-stripe clone.

SpyNote Adds Remote Control To The Attack

WindRelay becomes substantially more dangerous when paired with SpyNote.

SpyNote is a long-established Android RAT capable of providing attackers with extensive remote access to infected devices. Threat intelligence databases continue to track active SpyNote infrastructure and samples, demonstrating that the malware family remains relevant to the Android threat landscape.

In this campaign, SpyNote provides the remote-control layer while WindRelay performs the specialized NFC relay operation.

That combination gives criminals two very different capabilities inside one attack chain.

One component controls the phone.

The other weaponizes its NFC hardware.

Accessibility Services Become An

A particularly important part of the attack is Android’s Accessibility Service framework.

Accessibility features are legitimate and essential for users who need assistance operating their devices. Unfortunately, criminals frequently attempt to abuse the same capabilities because accessibility permissions can provide powerful control over applications and user-interface interactions.

According to the research described in the original report, SpyNote’s accessibility access can allow the attacker to sideload and activate the NFC component without requiring traditional screen-sharing behavior.

That makes the attack harder for an ordinary victim to recognize.

There may be no obvious remote desktop session. No attacker needs to visibly move the victim’s cursor. Instead, the malicious software can operate through Android’s own accessibility mechanisms.

The Attack Begins With Social Engineering

Technical malware is only one part of the operation.

The first step is often psychological.

Victims can be approached through phishing, smishing, or vishing campaigns. A criminal may impersonate a bank employee, fraud investigator, customer-support representative, or another trusted authority.

The victim is then persuaded to install an application.

The social-engineering component is particularly important because the attackers need the victim to perform an action that security software alone may not prevent.

The malicious APK may be presented as a banking application, security utility, identity-verification tool, or emergency account-protection application.

The victim believes they are cooperating with a legitimate financial institution.

In reality, they are giving the attacker a foothold inside their Android device.

Personalization Makes The Scam More Convincing

One of the most revealing details is that the malicious APK distributed during the phone interaction can be personalized with the victim’s name.

That suggests preparation before the call or message occurs.

A criminal who already knows the

Imagine receiving a call in which the supposed bank employee already knows your name, knows which number they contacted, and confidently explains that suspicious activity has been detected on your account.

The request to install an application may suddenly sound reasonable.

This is why modern mobile fraud cannot be treated solely as a malware problem. It is also an intelligence-gathering and psychological manipulation problem.

The Victim Is Asked To Tap Their Own Card

This is where

The victim may be instructed to place their physical payment card against the infected smartphone.

The criminal can disguise the action as part of an identity-verification process, PIN change, security check, or account-recovery procedure.

The victim is therefore not necessarily handing over their card.

They are voluntarily bringing the card close to a compromised NFC reader.

That subtle distinction is what makes this type of fraud so dangerous.

The physical card remains in the

How The NFC Relay Architecture Works

WindRelay uses two coordinated components.

The first is the reader component installed on the victim’s Android device.

Its job is to communicate with the physical payment card using NFC.

The second is the emulator component running on the attacker’s device.

Its purpose is to reproduce the card-side communication at a payment terminal.

Between these two components sits the

The system can use WebSocket communication to maintain a live connection between the reader and emulator.

EMV APDU commands and responses can then be relayed between the payment terminal and the victim’s physical card.

This is fundamentally different from simply stealing a card number and sending it to a criminal.

The attacker is attempting to preserve the live communication required for the contactless transaction.

Why Real-Time Relaying Matters

Payment cards use dynamic information during transactions, which means traditional concepts of card cloning do not always translate cleanly into the contactless environment.

NFC relay attacks work around this problem by forwarding communication while the transaction is happening.

The attacker does not necessarily need to understand every piece of the payment conversation.

They need to transport the conversation between two locations.

That turns distance into something the criminal can overcome.

A victim can be holding a physical card in one location while an attacker operates a payment terminal somewhere else.

Group-IB’s research describes this broader NFC relay model as a fundamental challenge to the assumption that physical proximity itself provides security for contactless payments.

Ghost Tap Is Becoming A Broader Criminal Ecosystem

The WindRelay operation is part of a much larger evolution commonly associated with Ghost Tap and NFC relay fraud.

Group-IB has documented an expanding ecosystem of Android NFC-enabled malware and criminal services, including dozens of APK variants and underground distribution channels. Its research found more than 54 distinct APK samples in one NFC fraud ecosystem and documented at least $355,000 in illegitimate transactions from a single POS vendor during November 2024 through August 2025.

The important point is that WindRelay is not appearing in isolation.

The criminal economy around NFC relay attacks is becoming increasingly specialized.

Developers can build the malware.

Affiliates can distribute it.

Social engineers can recruit victims.

Mules can perform purchases.

And other criminals can operate payment terminals.

The result resembles a supply chain rather than a traditional one-person cyberattack.

The Geography Of NFC Fraud Is Expanding

NFC relay malware was initially associated with campaigns concentrated in particular European markets, but the technique has increasingly appeared in other countries.

Researchers have documented related NFC relay activity involving countries including Czechia, Brazil, Poland, and Slovakia.

ESET also reported in April 2026 that a new NGate variant was being used against Android users in Brazil and was abusing a legitimate NFC application that had been modified with malicious code. The campaign demonstrated that attackers continue to experiment with different NFC relay implementations rather than relying on a single malware family.

This geographic expansion matters because the underlying technique is not tied to one bank or one country’s payment infrastructure.

Where Android NFC payments and contactless cards are widely used, the basic attack model can potentially be adapted.

WindRelay Creates Two Monetization Channels

The most concerning aspect of the operation is that attackers are not necessarily limited to payment fraud.

The RAT component can potentially support financial-account abuse, credential theft, remote interactions, and fraudulent applications.

The NFC component creates another monetization route through card-present transactions.

This produces a dual-fraud strategy.

One attack can target digital financial services while simultaneously targeting physical payment infrastructure.

Group-IB described this as a combination in which remote access can support fraudulent digital loans while NFC relay capabilities can enable card-present purchases.

The Attack Can Move Faster Than The Victim

Traditional fraud often gives banks time to react.

A suspicious login might trigger an alert.

An unusual transfer might be blocked.

A password reset might generate a notification.

NFC relay attacks introduce a different problem.

The criminal can attempt transactions while the victim is still on the phone with the supposed bank representative.

The social-engineering call becomes a race against the bank’s detection systems.

The longer the victim believes the caller is legitimate, the longer the attacker may have to operate.

Twenty-Three WindRelay Samples Show Continued Development

According to the original research, as many as 23 WindRelay samples were submitted to VirusTotal between November 2025 and July 2026.

The samples reportedly impersonated financial institutions in Czechia, Slovakia, and Slovenia.

That detail is significant because it suggests the operation is not merely an experimental malware project.

The malware is being adapted to a specific regional financial environment.

Brand impersonation can also make malicious applications more convincing during targeted social-engineering campaigns.

Android Security Is Facing A New Class Of Problem

Mobile security has traditionally focused heavily on credentials, malicious overlays, spyware, SMS interception, and banking trojans.

NFC relay malware changes the equation.

The attacker does not necessarily need to steal the card number in a conventional way.

The attacker wants access to the transaction itself.

That means security controls must increasingly understand the relationship between applications, NFC activity, accessibility permissions, device behavior, and financial transactions.

A malicious application requesting NFC access may not be suspicious by itself.

A malicious application requesting NFC access while another unauthorized application has remote-control capabilities is a much stronger signal.

Why Conventional Antivirus May Not Be Enough

Signature-based detection remains useful, but specialized malware can evolve quickly.

Attackers can modify application names, package structures, code, certificates, network infrastructure, and delivery mechanisms.

The more important defensive question becomes behavioral.

What application suddenly requested accessibility privileges?

What application was installed outside the official distribution channel?

Why is a remote-access trojan interacting with NFC functionality?

Why is NFC communication occurring immediately after a suspicious phone call?

Why is an Android device transmitting unusual data to an external WebSocket endpoint?

Security teams need to connect those events.

Banks Have A Role Beyond Transaction Monitoring

Financial institutions cannot rely entirely on customers to identify sophisticated social engineering.

Banks can potentially monitor unusual combinations of signals.

A card transaction from an unexpected location can be one signal.

A sudden account-recovery attempt can be another.

A new-device enrollment can be another.

Fraud detection becomes stronger when these events are analyzed together rather than independently.

The emergence of NFC relay attacks therefore creates pressure for banks to combine device intelligence, transaction intelligence, behavioral analytics, and customer-interaction signals.

Consumers Need To Recognize The Biggest Red Flag

The most important warning is simple.

A legitimate bank should not need you to install an unknown APK during an unsolicited phone call and then place your physical payment card against your phone for an emergency security procedure.

That combination should immediately end the conversation.

Do not continue because the caller knows your name.

Do not trust the caller because they know your bank.

Do not install an application because the caller claims it is required.

And do not tap your card against a phone simply because someone says it is necessary to protect your account.

What Undercode Say:

The Attack Is Bigger Than NFC

WindRelay is important because it demonstrates convergence.

Social Engineering Becomes The Entry Point

The criminal does not begin by breaking Android.

The criminal begins by breaking trust.

SpyNote Provides The Remote-Control Layer

The RAT gives the attacker a foothold inside the victim’s device.

WindRelay Provides The Financial Layer

The NFC component turns that foothold into a payment-relay mechanism.

Accessibility Becomes A Weapon

A legitimate Android accessibility feature can become dangerous when abused by malware.

Personalization Raises The Success Rate

Using a

The Victim Becomes Part Of The Attack

The victim may unknowingly perform the NFC tap themselves.

Physical Card Theft Is Not Required

The card can remain in the

Distance Is No Longer Reliable Protection

The payment terminal can be physically separated from the card.

The Criminal Controls The Other Endpoint

The attacker can use an emulator device to reproduce the payment interaction.

WebSockets Enable Live Communication

A persistent network connection allows the two sides of the relay to communicate.

APDU Relaying Is The Technical Core

The system forwards the commands and responses involved in the contactless transaction.

This Is Not Ordinary Credential Theft

The objective is not merely to learn a password.

The Payment Conversation Is The Target

The malware attempts to transport the live NFC exchange.

Ghost Tap Is Becoming Industrialized

Research has already shown dozens of related NFC malware variants and underground services.

Malware Development Is Becoming Modular

Criminals can combine existing RATs with specialized financial components.

Criminal Roles Can Be Separated

One actor can develop malware while another performs social engineering.

Payment Mules Add Another Layer

Fraudsters can use other individuals or networks to conduct physical transactions.

Financial Fraud Is Becoming Cross-Domain

Digital loans and physical card payments can be attacked in the same campaign.

Android Is A Strategic Target

The

Sideloading Remains A Major Weakness

Malicious APK installation bypasses some of the protections associated with trusted app distribution.

Users Often Trust Authority

A convincing caller can override technical caution.

Caller ID Is Not Proof

Phone numbers and identities can be spoofed or manipulated.

Knowing Personal Information Is Not Proof

Criminals can obtain names and phone numbers before making contact.

A Bank Brand Is Not Proof

Attackers can copy logos, terminology, application names, and scripts.

The Device Can Become The Payment Bridge

That is the defining danger of NFC relay malware.

Detection Must Become Behavioral

Security products need to understand combinations of actions.

Accessibility Plus NFC Deserves Attention

That pairing can be significantly more suspicious than either capability alone.

Remote Control Plus NFC Is Even More Significant

A RAT combined with payment functionality should trigger deeper investigation.

Banks Need Better Device Intelligence

Transaction monitoring alone cannot explain every modern mobile fraud event.

Mobile Security Teams Need NFC Telemetry

NFC-related behavior deserves greater visibility in enterprise and financial-security environments.

Users Need Better Education

Technical controls cannot completely compensate for persuasive social engineering.

Emergency Calls Should Trigger Skepticism

Pressure and urgency are common ingredients in financial scams.

APK Installation During A Call Is A Major Warning

Users should independently contact the institution before installing anything.

NFC Fraud Is Still Evolving

The discovery of new families demonstrates that criminals are actively experimenting.

Brazil Shows The Model Is Spreading

ESET’s 2026 NGate research demonstrates continued NFC relay activity outside the original European clusters.

The Criminal Economy Is Adapting

NFC relay capabilities are increasingly being packaged as usable fraud infrastructure.

The Next Stage Could Be Automation

Large numbers of compromised Android devices could theoretically support coordinated payment activity.

The Real Security Boundary Has Changed

Physical possession of a card no longer automatically guarantees physical control of every transaction involving it.

WindRelay Is A Warning About Convergence

The future of mobile financial malware is likely to combine several capabilities rather than depend on one payload.

The Strongest Defense Is Layered

Secure app distribution, permission controls, behavioral detection, fraud analytics, and user awareness must work together.

Deep Analysis: Detecting Suspicious Android Behavior

Investigate Recently Installed APKs

Security teams investigating a suspected Android infection should begin by identifying applications installed shortly before the fraudulent activity.

adb shell pm list packages -3

Review Installed Application Details

A suspicious package can then be examined for its metadata and installation information.

adb shell dumpsys package

Inspect Accessibility Services

Because accessibility abuse is an important component of many Android RAT campaigns, defenders should examine enabled accessibility services where device-management capabilities permit it.

adb shell settings get secure enabled_accessibility_services

Review Network Connections

Investigators can look for unusual active connections associated with suspicious applications or device behavior.

adb shell dumpsys connectivity

Inspect Running Processes

Unexpected background processes can provide another clue during incident response.

adb shell ps -A

Search Enterprise Telemetry For NFC Activity

Organizations with mobile telemetry should correlate NFC-related events with newly installed applications, accessibility changes, remote-control behavior, and suspicious network activity.

Hunt For WebSocket-Based C2

Because relay systems can maintain persistent communications, defenders should investigate unusual long-lived connections from applications that have no legitimate reason to maintain them.

Correlate Permission Changes

A sudden accessibility permission grant followed by NFC-related behavior should receive additional scrutiny.

Examine Application Provenance

An APK delivered through a phone call, text message, messaging platform, or unknown website should be treated as high risk, especially when it impersonates a financial institution.

Preserve Evidence Before Removing Malware

If an Android device is suspected of being involved in financial fraud, investigators should preserve relevant evidence before resetting the device whenever possible.

Use Known Indicators Carefully

Security teams should avoid treating one filename or package name as a complete detection strategy.

Modern Android malware frequently changes identifiers.

Build Behavioral Detections

A stronger detection might combine:

New APK installation

+

Accessibility privilege

+

NFC access

+

Remote-control capability

+

External C2 connection

=

High-risk mobile fraud behavior

Protect The Payment Layer

Banks and payment providers should investigate whether transaction risk models can detect impossible or unusual relationships between device location, card location, transaction location, and device identity.

Educate Customers Before Fraud Happens

The most effective intervention may occur before installation.

Customers should know that unsolicited callers requesting APK installation or unusual NFC card interactions are not following normal banking security procedures.

Accuracy Review

✅ Confirmed: NFC relay malware is a documented Android threat, and Group-IB has publicly documented Ghost Tap-style malware that relays NFC communications between victims and attacker-controlled devices.

✅ Confirmed: SpyNote is a real Android RAT family that remains represented in current threat-intelligence telemetry.

⚠️ Context: The specific WindRelay details, including the 23 samples and its exact SpyNote integration, come from the Group-IB research described in the source article; the broader NFC-relay threat is independently supported by Group-IB and ESET research.

Prediction

(+1) NFC Relay Fraud Will Become More Modular

Attackers are likely to continue combining established Android RATs with specialized NFC components instead of developing every capability inside one malware family.

(+1) Criminals Will Target More Countries

The appearance of related campaigns in Brazil and other regions suggests that NFC relay fraud is moving beyond a narrow geographic cluster.

(+1) Social Engineering Will Remain Central

Technical defenses can be bypassed when attackers persuade victims to install software and physically interact with their own payment cards.

(+1) Financial Malware Will Converge

Future campaigns may combine banking trojans, remote-access capabilities, identity theft, NFC relay, and fraudulent lending into a single coordinated operation.

(-1) Simple Signature Detection Will Become Less Effective

Malware developers can change application packaging and infrastructure faster than traditional signatures can always adapt.

(-1) Physical Card Possession Will Not Guarantee Safety

As relay technology improves, simply keeping the physical card in your wallet may not be sufficient protection against every form of contactless fraud.

Final Perspective: The Phone Is Becoming Part Of The Payment Attack Surface

WindRelay represents a deeper change in mobile financial crime.

The attacker is no longer necessarily trying to steal the card.

They may not even need to steal the card number.

Instead, they can attempt to turn the

That is what makes the combination of SpyNote and WindRelay so concerning.

The RAT controls the phone.

Social engineering controls the

NFC provides access to the payment channel.

The relay infrastructure connects the two locations.

And the criminal gets a pathway from a compromised Android device to the physical world.

The broader research already shows that NFC relay malware is developing rapidly, with multiple families, underground services, regional campaigns, and increasingly sophisticated delivery methods.

The lesson for consumers is brutally simple: never install an APK because an unsolicited caller tells you it is necessary to protect your bank account, and never tap your payment card against an unfamiliar phone as part of an emergency security procedure.

The lesson for security teams is even more important.

Mobile security can no longer stop at passwords, SMS messages, and banking applications.

The NFC layer itself has become part of the financial attack surface.

▶️ Related Video (74% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube