Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

WindRelay Android Malware: A Sophisticated Scheme of Contactless Payment Fraud and Remote Access


WindRelay Android malware, a sophisticated scheme of contactless payment fraud and remote access, has been deployed in conjunction with SpyNote, a known remote access trojan. The malware captures live card data via NFC and transmits it to fraudsters in real-time, enabling cybercriminals to carry out contactless payment fraud and remote access, expanding beyond the Czech Republic to Brazil, Poland, and Slovakia.

  • The WindRelay Android malware is a sophisticated NFC relay malware family that has been deployed with a remote access trojan (RAT) called SpyNote to carry out contactless payment fraud and remote access.
  • The malware was first detected in the wild in late August 2025 and is designed to capture live card data via NFC and transmit it to fraudsters in real-time.
  • The malware family uses personalized APK files to lend credibility to the scheme and to make the social engineering pretext more persuasive.
  • The victim's device is turned into a payment proxy without their awareness, serving as a live bridge for contactless payment fraud.
  • The malware incorporates two components that work in sync with each other: a reader component installed on the victim's device, which interfaces with the physical payment card via NFC, and an emulator component installed on the threat actor's device, which emulates the card at a payment terminal.
  • The primary advantage of this technique, also known as Ghost Tap, is that it allows cybercriminals to carry out cashouts at a larger scale.
  • The development of WindRelay Android malware targeting Android has proliferated, expanding beyond the Czech Republic to Brazil, Poland, and Slovakia over the past year.
  • The researchers have noted a potent combination of NFC relay and RAT capabilities, granting the attacker more ways to extract data, retain persistent access, and conduct financial fraud.
  • The case highlights the importance of modern fraud rarely relying on one technique and the need for continued vigilance and robust security measures to protect mobile devices and prevent such attacks.



  • The digital landscape has witnessed the emergence of numerous sophisticated malware schemes in recent times, each designed to infiltrate and exploit the vulnerabilities of mobile devices. Among the most recent and alarming cases is the WindRelay Android malware, a previously unseen near field communication (NFC) relay malware family that has been deployed in conjunction with a known remote access trojan (RAT) called SpyNote. This article aims to provide an in-depth analysis of the WindRelay Android malware, its impact on the security of mobile devices, and the methods employed by cybercriminals to carry out contactless payment fraud and remote access.

    The WindRelay Android malware was first detected in the wild in late August 2025. According to Group-IB, a cybersecurity company, the malware is designed to capture live card data via NFC and transmit it to fraudsters in real-time. The malware family is part of a contactless payment fraud scheme that involves luring prospective targets via phishing, smishing, or vishing scams into sideloading a malicious app. Once installed, the threat actor abuses SpyNote's remote access to install the NFC relay malware without any further user interaction.

    The researchers at Group-IB have highlighted the use of personalized APK files, which are tailored to each target, to lend credibility to the scheme. This personalized approach indicates a pre-call reconnaissance phase where the threat actor harvests the victim's name and phone number to make the social engineering pretext more persuasive. The victim is then socially engineered into tapping their physical payment card against their own infected phone under the pretext of identity verification or changing their PIN and verifying their banking card following a purported compromise of their account.

    Upon successful installation, the victim's device is turned into a payment proxy without their awareness, serving as a live bridge for contactless payment fraud. The malware intercepts and reads the card's radio signals using NFC and streams them in real-time to a fraudster's separate device elsewhere. The WindRelay malware incorporates two components that work in sync with each other: a reader component installed on the victim's device, which interfaces with the physical payment card via NFC, and an emulator component installed on the threat actor's device, which emulates the card at a payment terminal.

    These two components interact through a shared command-and-control (C2) infrastructure over WebSocket, relaying EMV APDU commands and responses between the terminal and the victim's card in real-time. This method of contactless payment fraud allows cybercriminals to stay anonymous and perform cashouts at a larger scale as capturing the NFC data of banking customers enables them to mimic their bank card on their own device and use it for cash withdrawals or to make payments.

    The primary advantage of this technique, also known as Ghost Tap, is that it allows cybercriminals to carry out cashouts at a larger scale as capturing the NFC data of banking customers makes it possible to mimic their bank card on their own device and use it for cash withdrawals or to make payments. The development of WindRelay Android malware targeting Android has proliferated, expanding beyond the Czech Republic to Brazil, Poland, and Slovakia over the past year.

    The latest findings from Group-IB demonstrate a potent combination of NFC relay and RAT capabilities, granting the attacker more ways to extract data, retain persistent access, and conduct financial fraud. As many as 23 WindRelay samples have been uploaded to VirusTotal between November 2025 and July 2026, impersonating financial institutions in Czechia, Slovakia, and Slovenia.

    The researchers at Group-IB have noted that this represents a new evolution of Android malware and a dual monetization strategy within a single scheme, where RAT-driven remote access can be used to take out a digital loan, while the NFC malware enables physical, card-present purchases. The case also highlights the importance of modern fraud rarely relying on one technique. In this instance, the fraudster combined three capabilities in a single session: a live social engineering call, a personalized RAT for remote device control, and an NFC relay malware for physical cashout.

    The fraudster also used these capabilities to hit two separate payout channels – a digital loan and card-present purchases – before the bank or victim could react. The WindRelay Android malware serves as a prime example of the sophisticated and evolving nature of cybercrime, highlighting the need for continued vigilance and robust security measures to protect mobile devices and prevent such attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/WindRelay-Android-Malware-A-Sophisticated-Scheme-of-Contactless-Payment-Fraud-and-Remote-Access-ehn.shtml

  • https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html


  • Published: Mon Aug 17 10:25:15 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us