WindRelay is an Android NFC relay malware family used for contactless-payment fraud. It captures the live NFC exchange between a victim’s physical payment card and an infected Android device, then relays EMV commands and responses in real time to an attacker-controlled device that can present the card interaction to a merchant terminal or contactless ATM. This real-time relay permits fraudulent card-present transactions using transaction-specific payment data rather than reusable static card details.
WindRelay has been deployed with the SpyNote remote-access trojan in telephone-based bank-impersonation scams. Victims are persuaded during a live call to sideload a personalized SpyNote application and grant Accessibility permissions. Operators then use SpyNote’s device-control capability to silently install and activate WindRelay. Victims are instructed to tap their payment card to the phone and enter its PIN, while the attackers relay the contactless transaction to conduct fraudulent purchases or withdrawals. The same remote access has also been used to access mobile banking applications and carry out lending fraud.
WindRelay activity has been associated with campaigns impersonating financial institutions and targeting Android users in Czechia, Slovakia, and Slovenia. The malware exemplifies the Ghost Tap category of NFC relay fraud, combining social engineering, remote device takeover, and a direct card-present cash-out mechanism.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
In a report published August 12, 2026, the firm said it identified 23 samples uploaded to VirusTotal between November 2025 and July 2026 and four command-and-control (C2) IP addresses.
They dubbed it “WindRelay.” ... capture live card data via NFC and forward it in real time to attackers... That tap let the second app forward the card’s contactless data in real time to the criminals
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android NFC relay malware remotely deployed after device takeover. It captures and relays victims' live NFC payment-card data to attacker-controlled devices, enabling unauthorized purchases or cash withdrawals.
Android NFC-relay malware installed after fraudsters obtain remote access to a victim device. It relays card data to a fraudulent merchant terminal so transactions can be approved with the victim-entered PIN.
Referenced as a similar 2026 Android malware discovery; described only as NFC relay malware.
Newly identified Android NFC relay malware that captures and remotely relays contactless payment card data to facilitate fraudulent transactions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.