WindRelay: a 13-minute call turns a phone into a card relay
Group-IB documented NFC relay malware that captures a live contactless card tap and replays it on another device. The whole chain is one sideloaded APK.
A caller says they're from your bank. Thirteen minutes later they have taken out a loan in your name and are tapping your card at a store you have never been to. That is not a hypothetical — it is the case Group-IB walked through this week, tracking new NFC relay malware it calls WindRelay. For anyone who takes contactless payments, the interesting part isn't the malware. It's that a normal-looking tap at your terminal can now be a card that is nowhere near your store.
What actually happened
Group-IB published its technical writeup on August 12. The chain it documented:
- A live voice call. An attacker impersonating a bank employee talks the victim through installing an Android app. The first payload is a personalized SpyNote variant — the app label uses the victim's own name, so a sideloaded APK looks familiar instead of suspicious.
- Accessibility abuse. SpyNote uses Android's Accessibility Service permissions to silently install a second app: WindRelay. The victim never approves it.
- The tap. The victim is told to hold their physical card against the phone and enter their PIN, framed as verifying or securing the card.
- The relay. WindRelay captures the live EMV contactless exchange and relays it through attacker infrastructure to a second Android device, which is what actually presents the card.
In the case Group-IB investigated, the attackers also used their access to take out a digital loan through the victim's own banking app — account takeover and physical cash-out in one session.
Scope, per Group-IB: 23 samples uploaded to VirusTotal between November 2025 and July 2026, impersonating financial institutions in Czechia, Slovakia, and Slovenia. The firm first spotted the family in late August 2025.
Why NFC relay fraud matters for your business
Two things, and neither requires you to be a bank.
Your terminal can't tell. A relayed tap is a real card doing a real EMV exchange. Your reader sees a valid contactless transaction. Detection has to come from your processor's fraud signals — velocity, geography, card-not-typical patterns — which means knowing what your processor actually flags and whether anyone reads those alerts. If the answer is "nobody," that's a fifteen-minute fix.
The attack chain is the boring part. Phone call, sideloaded APK, accessibility permissions. Nothing exotic. That same chain works against your staff — it's how the Brinks Home breach ran, and it's how most vishing lands. On any company Android: block sideloading, lock down Accessibility Service grants, and enforce it with policy rather than a memo. And write down the rule your team can repeat under pressure — a caller who wants you to install something is the attack, every time.
Key takeaways
- WindRelay relays a live contactless card exchange to a second Android device that presents the card
- Delivery is a vishing call plus a sideloaded SpyNote APK labeled with the victim's own name
- SpyNote uses Accessibility Service permissions to install WindRelay with no user approval
- Group-IB found 23 samples from Nov 2025 to Jul 2026 targeting Czechia, Slovakia, and Slovenia
- Block sideloading and Accessibility grants on company Androids; know what your processor flags
Not sure what your payment stack would catch? We audit the systems a small business actually runs on — POS, processor alerts, staff devices — and fix the gaps in the order they'd get exploited. Tell us what you're running, or see what we've built for other operators.
Sources: Group-IB — Gone with the WindRelay, The Hacker News.
- #nfc-relay
- #payment-fraud
- #android-malware
- #vishing
- #retail-security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Grubhub's $23.8M FTC refunds: listed without consent
The FTC is mailing 640,038 payments over Grubhub's conduct, including listing up to 325,000 restaurants that never signed up. What that means for your storefront.
Read itWhatnot's $545M at $20B: live commerce is a real channel
Whatnot raised $545M at a $20B valuation on $8B of first-half GMV. What the live commerce numbers mean for small sellers picking a channel.
Read it