www.malwarebytes.com 8/13/2026, 12:11:02 PM · external

WindRelay malware steals live card data via NFC relay attack

WindRelay malware steals live card data via NFC relay attack
Developing story malware 2 articles tracked
WindRelay NFC malware steals live card data via relay attack
CyberSIXT Evidence Panel
Primary Source group-ib.com

A new Android malware, named "WindRelay," enables criminals to steal live card data via NFC (Near Field Communication) technology. Researchers from Group-IB reported that attackers can capture card data from an infected phone and relay it to a criminal-controlled device near a payment terminal. This malware works in conjunction with a remote access Trojan (RAT) called SpyNote, which allows attackers to gain control of the victim's phone seamlessly.

In a typical attack, victims are tricked into downloading an app disguised as their bank's app, which then facilitates the installation of WindRelay. Attackers communicate with victims over the phone to guide them through steps that include tapping their physical bank card against the infected device.

The key mechanism of WindRelay lies in its ability to relay dynamic codes used in contactless payments in real time, making it effective against advanced fraud detection systems. Even with the challenge posed by dynamic codes, timing is crucial, and the attackers use phone calls to overcome the victim's hesitation and ensure precise coordination.

To protect against such attacks, individuals are advised to be cautious of unsolicited communications, verify requests through official channels, refrain from sideloading applications, and maintain up-to-date anti-malware software.

View Primary Source Via www.malwarebytes.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline