WindRelay Android Malware Exploits NFC for Real-Time Card Data Theft
New Android malware dubbed WindRelay leverages NFC and social engineering to steal payment card data in real-time, even while victims hold their cards.

Researchers have uncovered a novel Android malware named WindRelay that poses a significant threat to payment card security by exploiting Near Field Communication (NFC) technology. Unlike traditional data theft methods, WindRelay enables attackers to capture and relay a victim's payment card data in real-time, even while the victim is in physical possession of their card.
The sophisticated attack chain begins with a social engineering tactic. Fraudsters impersonate bank representatives, contacting victims with fabricated stories about issues with their payment cards. During this call, the attackers guide the victims through installing an application, which is in fact the SpyNote remote access trojan (RAT). To lower the victim's guard, the SpyNote app is customized with the victim's own name as its label, making it appear legitimate.
Once SpyNote establishes remote access to the compromised device, the attackers can install the WindRelay malware without any further interaction from the victim. WindRelay then utilizes the device's NFC capabilities to communicate with the victim's payment card. Simultaneously, it uses an internet connection to relay the captured transaction data to the attackers as it happens. The malware also requests unusual permissions, including access to the victim's contacts and system-inspection capabilities.
Group-IB researchers detailed a harrowing example where a victim, over a 13-minute phone call, installed the RAT and subsequently had a loan taken out in their name via their mobile banking app. The fraudster then streamed the victim's card data to a fake merchant terminal, with transactions approved using the victim's own PIN, all while the victim remained on the call. Card transactions began appearing on the victim's account shortly after the call concluded.
Analysis of WindRelay samples uploaded to VirusTotal between November 2025 and July 2026 revealed campaigns targeting victims in Czechia, Slovakia, and Slovenia. Several samples were tailored with victim-specific names and interface text matching the local language, indicating a localized and personalized approach by the threat actors.
This attack highlights a concerning convergence of multiple malicious techniques. The fraudster combined live social engineering, a personalized RAT for remote device control, and an NFC relay malware for a physical cash-out mechanism. This multi-faceted approach significantly increases the likelihood of a successful attack and makes it harder for victims to detect and prevent.
The discovery of WindRelay underscores the evolving landscape of mobile banking fraud. As NFC technology becomes more ubiquitous, it also presents new avenues for exploitation by sophisticated threat actors. The reliance on social engineering to trick victims into installing malware remains a critical vulnerability, amplified by the real-time data exfiltration capabilities of WindRelay.