Listen to this Post

A new Android malware, named RelayNFC, has emerged in Brazil, raising alarm among cybersecurity experts and mobile banking users. Unlike traditional malware, RelayNFC operates in real-time, relaying Near Field Communication (NFC) APDU commands via WebSockets. This capability allows cybercriminals to perform remote contactless payments, essentially turning an infected device into a proxy for illicit financial transactions. The malware leverages Hermes bytecode, a technology often used to obfuscate malicious operations, and is experimenting with Host Card Emulation (HCE) to manipulate NFC transactions more effectively.
RelayNFC Malware: How It Works
RelayNFC’s design revolves around intercepting and transmitting NFC commands in real-time. Normally, NFC-enabled devices communicate directly with payment terminals for transactions. RelayNFC sits between the device and the terminal, capturing APDU commands—the standardized messages used in card communication—and sending them to a remote attacker via WebSockets. This essentially allows the hacker to trigger transactions from anywhere in the world, bypassing physical proximity requirements typical of NFC payments.
The malware also integrates Hermes bytecode, which adds a layer of complexity to its code execution. This makes analysis more challenging for cybersecurity teams, enabling the malware to remain hidden in the device while performing continuous operations. Early reports suggest that RelayNFC experiments with Host Card Emulation, a method that mimics a physical card in software. If successful, attackers could potentially emulate payment cards directly on compromised devices without needing the victim’s physical card.
Brazil has seen a growing trend of mobile-targeted financial malware in recent years, with attackers increasingly focusing on contactless and digital payment systems. RelayNFC represents a sophisticated evolution in this space, combining remote command execution with advanced code obfuscation and emulation techniques.
Potential Impacts on Mobile Security
The emergence of RelayNFC highlights vulnerabilities in mobile payment ecosystems. Users could unknowingly have their devices relay sensitive payment information to attackers, leading to unauthorized transactions, financial losses, and breaches of personal data. Moreover, the malware’s ability to function in real-time through WebSockets increases the speed and scale at which attackers can operate.
Financial institutions and mobile payment providers are now under pressure to enhance NFC security protocols and implement advanced detection mechanisms to prevent relay-based attacks. Meanwhile, Android users in Brazil are advised to maintain strict app permissions, avoid unofficial app stores, and monitor financial accounts closely.
What Undercode Say:
RelayNFC is a clear example of modern financial malware innovation. By using NFC relaying and HCE experimentation, it demonstrates that cybercriminals are no longer limited by physical proximity; remote attacks on contactless payments are now feasible. This marks a paradigm shift in mobile malware tactics, merging classic relay attacks with emerging Android technologies.
The integration of Hermes bytecode further indicates that attackers are prioritizing stealth and persistence. Bytecode-based malware is harder to reverse-engineer, complicating incident response and forensic investigations. Analysts should anticipate a rise in similar malware that combines code obfuscation with advanced exploitation of mobile payment protocols.
From a behavioral perspective, RelayNFC represents adaptive cybercrime. Attackers are clearly targeting regions with high adoption of NFC payments, like Brazil, and designing malware specifically to bypass standard user verification and transaction safeguards. This underlines the growing importance of device-level security measures, such as real-time monitoring of NFC activity, anomaly detection in payment apps, and stricter HCE usage policies.
The malware also illustrates a potential future risk for global NFC systems. If techniques like those used in RelayNFC are refined, other countries with widespread contactless payment adoption could become targets. Android users worldwide should be aware that mobile payment malware is evolving beyond phishing and traditional banking Trojans, entering a new stage of remote, real-time attack capability.
Financial institutions must respond by integrating transaction behavior analytics, anomaly detection, and multi-factor authentication tailored to contactless payments. Additionally, educating users about the risks of granting excessive permissions to apps and encouraging regular device updates will be crucial in mitigating threats.
Fact Checker Results:
✅ RelayNFC relays NFC APDU commands in real-time — Confirmed
✅ Uses Hermes bytecode and experiments with HCE — Confirmed
❌ No evidence yet of large-scale financial losses reported
Prediction:
Given the sophistication of RelayNFC, we can expect more mobile malware leveraging NFC and HCE technologies. Attackers will likely expand globally, targeting any region with high contactless payment usage. Financial institutions may be forced to implement real-time NFC transaction monitoring and stronger app-level security measures to stay ahead. 💳
If you want, I can also reformat this into a more visual, article-ready layout with subheadings and bullet points to make it easier for readers to digest. Do you want me to do that next?
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




