A previously unknown Android malware family called WindRelay is being used alongside a remote access trojan to turn victims' phones into contactless payment fraud relays, according to a new report from Group-IB. The custom-built malware captures live payment card data through near field communication and sends it to fraudsters in real time. Researchers first spotted WindRelay circulating in the wild in late August 2025.

The attack unfolds through social engineering calls that trick victims into installing a malicious app via phishing, smishing, or voice scams. Once the app is on the device, the threat actor uses SpyNote—a known remote access trojan—to silently install the NFC relay malware without triggering any screen sharing or further user interaction. Victims are then manipulated into tapping their physical payment card against their own compromised phone, believing they're verifying their identity or changing a PIN after a fake account breach. The APK files distributed during these calls are personalized with each victim's name, signaling that attackers conduct reconnaissance to harvest names and phone numbers before making contact. Between November 2025 and July 2026, 23 WindRelay samples appeared on VirusTotal, impersonating banks in Czechia, Slovakia, and Slovenia.

The malware operates through two synchronized components, according to Group-IB researchers Alexander Grabko, Konstantinos Angelopoulos, Pavlos Gaitanis, and Bruno Bijelić: a reader installed on the victim's device that interfaces with the physical card via NFC, and an emulator on the attacker's device that mimics the card at a payment terminal. "SpyNote's Accessibility Service access lets the fraudster sideload and activate the NFC app silently, with no screen sharing ever triggered," the researchers said. These components communicate through a shared command-and-control infrastructure over WebSocket, relaying EMV APDU commands and responses between the terminal and the victim's card in real time. Group-IB noted this represents "a new evolution of Android malware and a dual monetization strategy within a single scheme," where remote access can be exploited to secure a digital loan while the NFC malware enables physical, card-present purchases.

The technique—also known as Ghost Tap—allows cybercriminals to stay anonymous and scale up cashouts by capturing banking customers' NFC data and mimicking their cards on separate devices for cash withdrawals or purchases. NFC relay malware targeting Android has spread beyond the Czech Republic to Brazil, Poland, and Slovakia over the past year. The researchers emphasized that "modern fraud rarely relies on one technique," pointing out that this scheme combines a live social engineering call, a personalized remote access trojan for device control, and NFC relay malware for physical cashout. The fraudsters also exploit two separate payout channels—digital loans and card-present purchases—before banks or victims can respond. For enterprises and financial institutions, the question isn't whether fraud will evolve but whether defenses can adapt quickly enough to counter layered, multi-vector schemes before customer trust erodes. The convergence of social engineering and malware automation suggests that traditional security perimeters may need rethinking as attackers optimize for speed and anonymity over sophistication.