Skip to content
Rush Commerce
Commerce & Retail Tech3 min read

WindRelay: a 13-minute call turns a phone into a card relay

Group-IB documented NFC relay malware that captures a live contactless card tap and replays it on another device. The whole chain is one sideloaded APK.

A caller says they're from your bank. Thirteen minutes later they have taken out a loan in your name and are tapping your card at a store you have never been to. That is not a hypothetical — it is the case Group-IB walked through this week, tracking new NFC relay malware it calls WindRelay. For anyone who takes contactless payments, the interesting part isn't the malware. It's that a normal-looking tap at your terminal can now be a card that is nowhere near your store.

What actually happened

Group-IB published its technical writeup on August 12. The chain it documented:

  1. A live voice call. An attacker impersonating a bank employee talks the victim through installing an Android app. The first payload is a personalized SpyNote variant — the app label uses the victim's own name, so a sideloaded APK looks familiar instead of suspicious.
  2. Accessibility abuse. SpyNote uses Android's Accessibility Service permissions to silently install a second app: WindRelay. The victim never approves it.
  3. The tap. The victim is told to hold their physical card against the phone and enter their PIN, framed as verifying or securing the card.
  4. The relay. WindRelay captures the live EMV contactless exchange and relays it through attacker infrastructure to a second Android device, which is what actually presents the card.

In the case Group-IB investigated, the attackers also used their access to take out a digital loan through the victim's own banking app — account takeover and physical cash-out in one session.

Scope, per Group-IB: 23 samples uploaded to VirusTotal between November 2025 and July 2026, impersonating financial institutions in Czechia, Slovakia, and Slovenia. The firm first spotted the family in late August 2025.

Why NFC relay fraud matters for your business

Two things, and neither requires you to be a bank.

Your terminal can't tell. A relayed tap is a real card doing a real EMV exchange. Your reader sees a valid contactless transaction. Detection has to come from your processor's fraud signals — velocity, geography, card-not-typical patterns — which means knowing what your processor actually flags and whether anyone reads those alerts. If the answer is "nobody," that's a fifteen-minute fix.

The attack chain is the boring part. Phone call, sideloaded APK, accessibility permissions. Nothing exotic. That same chain works against your staff — it's how the Brinks Home breach ran, and it's how most vishing lands. On any company Android: block sideloading, lock down Accessibility Service grants, and enforce it with policy rather than a memo. And write down the rule your team can repeat under pressure — a caller who wants you to install something is the attack, every time.

Key takeaways

  • WindRelay relays a live contactless card exchange to a second Android device that presents the card
  • Delivery is a vishing call plus a sideloaded SpyNote APK labeled with the victim's own name
  • SpyNote uses Accessibility Service permissions to install WindRelay with no user approval
  • Group-IB found 23 samples from Nov 2025 to Jul 2026 targeting Czechia, Slovakia, and Slovenia
  • Block sideloading and Accessibility grants on company Androids; know what your processor flags

Not sure what your payment stack would catch? We audit the systems a small business actually runs on — POS, processor alerts, staff devices — and fix the gaps in the order they'd get exploited. Tell us what you're running, or see what we've built for other operators.

Sources: Group-IB — Gone with the WindRelay, The Hacker News.

  • #nfc-relay
  • #payment-fraud
  • #android-malware
  • #vishing
  • #retail-security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.