Skip to Content
Join the Network with Us — Join Membership


New Android Malware Turns Phones Into Fraudulent Contactless Card Readers

August 13, 2026

A new Android malware strain called WindRelay is being used alongside the SpyNote remote administration tool to steal payment card data and relay it to attackers in real time — effectively allowing fraudulent transactions to go through genuine payment terminals as if nothing were wrong.

How the Scam Actually Plays Out

In one case investigated by cybersecurity firm Group-IB, a fraudster posed as a bank employee and called a victim, claiming there was a problem with their payment card. The victim was persuaded to install SpyNote, disguised as a legitimate application, and grant it Accessibility Service permissions — which effectively handed the attacker remote control of the Android device. In a particularly convincing touch, the attacker even personalised the malicious app's label with the victim's own name.

From Remote Access to a Fraudulent Card Reader

Once remote access was established through SpyNote, the attacker quietly installed WindRelay without needing any further action from the victim. The attacker then used the victim's own banking app to take out a loan in the victim's name. On top of that, the victim was instructed to tap their payment card against the now-compromised phone and enter the card PIN.

This is where WindRelay's real trick comes in — it effectively turned the victim's Android device into a fraudulent contactless card reader. The malware captured the live NFC exchange between the card and the phone, including transaction-specific authentication data, and relayed all of it to a device controlled by the attacker in real time. That stolen information was then used to make purchases at an actual, genuine payment terminal elsewhere. According to Group-IB, this entire operation unfolded during a single 13-minute phone call, with transactions approved using the very PIN the victim had unknowingly supplied.

A New Route for NFC-Based Financial Fraud

The combination of SpyNote and WindRelay gives attackers a particularly dangerous one-two punch — remote access to a victim's device, paired with a direct way to exploit payment card data. Android NFC relay attacks like this typically rely heavily on social engineering, convincing victims to install a malicious app, grant NFC access, and physically tap their payment cards against an infected phone.

Once that happens, the phone communicates with the contactless card via NFC and transmits the captured card information over the internet to another device controlled by the attacker. Depending on exactly what information gets captured and how it's used, the stolen data can potentially support fraudulent transactions and other forms of financial theft. It's worth noting that SpyNote and related malware variants, including SpyMax and CypherRAT, have actually been circulating since at least 2021 — this campaign represents a newer, more sophisticated use of that existing malware family.

Where This Campaign Is Focused

Group-IB identified nearly two dozen WindRelay samples submitted to VirusTotal between November 2025 and July 2026, communicating with four command-and-control IP addresses. Based on the organisations being impersonated and the languages used in these attacks, the targeting appears concentrated on Czechia, Slovakia, and Slovenia.

Staying Safe

Android users are advised to avoid installing APK packages from outside Google Play unless they know and genuinely trust the publisher, and to be especially cautious whenever an app requests NFC access or other sensitive permissions. If you receive an urgent call claiming to be from your bank, the safest move is to simply end the call and independently contact the institution using the number published on its official website — rather than following any instructions given by the caller, however convincing they might sound.

FAQs

Q1. How does the WindRelay malware steal payment card information?

WindRelay turns an infected Android phone into a fraudulent contactless card reader, capturing live NFC data exchanged when a victim taps their card against the phone, and relaying it to the attacker in real time.

Q2. How do attackers typically gain access to install this malware?

Attackers use social engineering, often posing as bank employees, to convince victims to install a disguised app like SpyNote and grant it Accessibility Service permissions, giving them remote control of the device.

Q3. Which regions have been targeted by the WindRelay campaign?

Based on the organisations impersonated and languages used, the campaign appears concentrated on Czechia, Slovakia, and Slovenia.

in News
Share this post
Archive