← Back to feed
Threat Actors & CampaignsEmerging2 sourcesAug 13, 2026 · 11:34via Malwarebytes Labs

New Android malware lets criminals use your bank card in real time

Brief

Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.”

NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together.

So, instead of stealing your physical bank card, the attackers capture NFC activity on an infected mobile phone and relay it in real time to a criminal-controlled device held against a contactless payment terminal, or an ATM that supports contactless cash withdrawals.

The researchers describe a 13-minute call impersonating a bank, in which a victim was persuaded to install an Android app labelled with the bank’s name. That app was a remote access Trojan (RAT) called SpyNote .

Read more on Malwarebytes Labs

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

Malwarebytes LabsPrimary··trust 1.28

New Android malware lets criminals use your bank card in real time

Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.”

NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together.

So, instead of stealing your physical bank card, the attackers capture NFC activity on an infected mobile phone and relay it in real time to a criminal-controlled device held against a contactless payment terminal, or an ATM that supports contactless cash withdrawals.

The researchers describe a 13-minute call impersonating a bank, in which a victim was persuaded to install an Android app labelled with the bank’s name. That app was a remote access Trojan (RAT) called SpyNote . SpyNote gave the attacker remote control of the phone and enabled the quiet installation of a second app, WindRelay .

The attackers then opened the victim’s legitimate banking app remotely and arranged a loan in the victim’s name, while also asking them to tap their physical payment card against the phone and enter its PIN. That tap let the second app forward the card’s contactless data in real time to the criminals, allowing them to make purchases or, in some cases, withdraw cash from an ATM.

This division of tasks is the important development here. The remote-access malware (SpyNote) gets the attackers into the phone, and the NFC relay malware (WindRelay) turns the victim’s physical card into something the criminals can use elsewhere at that moment.

It’s not quite as simple as it sounds, because NFC comes in a few different “flavors.” Some produce a static code. Take the card that opens my apartment building door, for example. That kind of signal can easily be copied to a device like my Flipper Zero so I can use it to open the door. But sophisticated contactless payment cards use dynamic codes.

Read more →
Malware.news··trust 0.88

New Android malware lets criminals use your bank card in real time

Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.”

NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together.

So, instead of stealing your physical bank card, the attackers capture NFC activity on an infected mobile phone and relay it in real time to a criminal-controlled device held against a contactless payment terminal, or an ATM that supports contactless cash withdrawals.

The researchers describe a 13-minute call impersonating a bank, in which a victim was persuaded to install an Android app labelled with the bank’s name. That app was a remote access Trojan (RAT) called SpyNote . SpyNote gave the attacker remote control of the phone and enabled the quiet installation of a second app, WindRelay .

The attackers then opened the victim’s legitimate banking app remotely and arranged a loan in the victim’s name, while also asking them to tap their physical payment card against the phone and enter its PIN. That tap let the second app forward the card’s contactless data in real time to the criminals, allowing them to make purchases or, in some cases, withdraw cash from an ATM.

This division of tasks is the important development here. The remote-access malware (SpyNote) gets the attackers into the phone, and the NFC relay malware (WindRelay) turns the victim’s physical card into something the criminals can use elsewhere at that moment.

It’s not quite as simple as it sounds, because NFC comes in a few different “flavors.”

Read more →