RelayNFC is an Android mobile malware family used for near-field communication relay fraud against contactless payment cards. It is associated with phishing-led campaigns, including operations targeting Brazilian users in late 2025, and has been discussed alongside other NFC-focused Android threats such as NGate, SuperCard X, and NFCShare.
The malware masquerades as a payment-card security or verification application and is delivered through phishing infrastructure and decoy Portuguese-language lures. Once installed, it abuses the device’s NFC functionality to capture payment-card communications and relay application protocol data unit exchanges in real time to attacker-controlled systems. This enables remote fraudulent transactions that emulate physical card presence at legitimate payment terminals. Observed attack flows also involve social engineering to persuade victims to tap their payment card against the infected phone and provide the card PIN, allowing the operators to complete unauthorized contactless purchases.
RelayNFC has been described as lightweight and evasive, with implementations built using React Native and Hermes-compiled components that complicate static analysis. Reported variants use a JavaScript-based logic layer and WebSocket-backed relay channels for live NFC data forwarding. Some reporting also indicates experimentation with Host Card Emulation to expand future fraud capabilities.
The malware’s primary objective is theft and misuse of contactless payment data rather than broad device compromise. Targeting has been especially noted in Brazil, particularly against banking and payment users, and the activity reflects a broader criminal trend toward mobile-enabled financial fraud using NFC relay techniques.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
El phishing fue el método más utilizado para el acceso inicial... Estos actores suelen recurrir a métodos de acceso inicial tradicionales, como phishing por correo electrónico, SMS y mensajes de WhatsApp, suplantando la identidad de instituciones financieras y solicitando facturas o pagos.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an example of Android NFC malware family.
Referenced as Android malware involved in NFC payment relay schemes used to abuse stolen payment card data.
Mobile malware targeting contactless payment cards, deployed in phishing campaigns against Brazilian users.
Malware móvil usado en campañas de phishing para atacar tarjetas de pago sin contacto mediante abuso de NFC.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.