A new malware campaign dubbed RelayNFC has been uncovered in Brazil, targeting users through phishing sites that distribute a malicious app masquerading as a payment card security tool. The app, once installed, captures victims' card details and enables attackers to conduct fraudulent transactions by relaying card data in real time, effectively mimicking the physical presence of the card. The malware is notable for its lightweight, evasive design, utilizing a Hermes-compiled payload and a JavaScript engine to remain undetected by security tools, with zero detections reported on VirusTotal at the time of discovery.
The campaign reflects a broader trend of NFC-based attacks, with other malware strains such as Ngate and SuperCardX also exploiting NFC capabilities for financial fraud. The use of phishing as the primary distribution method highlights the importance of user vigilance and the need for robust device-level protections. Financial institutions are advised to strengthen monitoring and detection mechanisms to address the evolving threat landscape posed by sophisticated NFC relay malware like RelayNFC.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC published its 'Mobile Security & Malware Issue 4st Week of November, 2025' roundup, indicating coverage of Android malware themes including Hermes malware, smishing, APK-based distribution, GitHub, and the Google Play Store. The brief notice does not provide enough detail to confirm a separate RelayNFC event beyond broader mobile malware reporting.
Cyble Research and Intelligence Labs reported a new NFC relay attack campaign dubbed RelayNFC targeting users in Brazil. The operation uses phishing sites to distribute a malicious Android app posing as a payment-card security tool in order to capture victims' card data for fraudulent transactions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.