All incidents

WindRelay NFC malware steals live card data via relay attack

malwareopenAug 12, 2026 — Aug 13, 2026
WindRelay NFC malware steals live card data via relay attack

A newly discovered Android malware called WindRelay is being used to capture live payment card data through NFC and relay it to attacker‑controlled devices near payment terminals, according to research from Group‑IB. It works together with the SpyNote remote access trojan to take full control of the victim’s phone and trick users into installing a fake bank app.

The malware arrives as an app that mimics a legitimate banking application; once installed it waits for the victim to tap their physical card against the infected phone, at which point WindRelay reads the NFC data and sends it in real time to a criminal‑controlled device positioned near a terminal, as detailed by Malwarebytes. The relay mechanism allows the stolen data to be used instantly at a contactless terminal, enabling fraudulent purchases before the victim realizes the card has been compromised.

No CVE has been assigned to the technique; instead the attack depends entirely on social engineering, with fraudsters posing as bank employees during phone calls and guiding victims to download the malicious app from unofficial sources, a tactic highlighted in Infosecurity Magazine reporting. Because no software vulnerability is exploited, traditional patching does not stop the scheme, making user awareness the primary defence.

Group‑IB observed the campaign between 12 August 2026 and 13 August 2026, during which criminals used the relay to make unauthorized payments and even open loans via the victim’s banking app. No specific threat actor has been linked to the activity, but the method mirrors other NFC‑relay fraud schemes seen in the wild.

Users should only install applications from official app stores, verify the developer name and reviews before granting any permissions, and avoid tapping a payment card against their phone while on an unsolicited call. Enabling transaction alerts and using NFC‑blocking sleeves can help detect and prevent unauthorized use of card data.

Security teams can educate customers about the scam, monitor for anomalous NFC traffic on managed devices, and deploy mobile threat defence solutions that block installation from unknown sources and detect known RAT behaviours such as SpyNote. Additionally, organisations should consider disabling NFC on corporate‑issued devices when not required for business functions and employ mobile threat defence tools that flag installation attempts from third‑party stores.

Intelligence briefing updated Aug 13, 2026

Root sourcewww.group-ib.com
Timeline Coverage

Swipe to explore timeline