Researchers at Group-IB have uncovered a new NFC relay malware family purpose-built to capture live card data and forward it in real time to attackers, dubbed "WindRelay."
NFC (Near Field Communication) allows devices like smartphones, payment cards, and payment terminals to communicate at close range. Rather than stealing a physical card, attackers capture NFC activity on an infected phone and relay it instantly to a criminal-controlled device held against a contactless terminal or an NFC-enabled ATM.
The attack begins with social engineering: researchers describe a 13-minute call impersonating a bank, persuading the victim to install an app labeled with the bank's name. That app was actually SpyNote, a remote access Trojan (RAT) that gave attackers full control of the phone and let them quietly install a second app, WindRelay.
With remote access secured, attackers opened the victim's legitimate banking app to arrange a loan in the victim's name, while separately instructing them to tap their physical payment card against the phone and enter its PIN. That tap let WindRelay capture the card's contactless data and forward it in real time, letting criminals make purchases or withdraw cash from an ATM elsewhere.
This division of labor is the key development: SpyNote gets attackers inside the phone, while WindRelay turns the victim's physical card into something usable elsewhere at that exact moment.
The timing matters because modern payment cards use dynamic security codes — unlike static NFC signals (like a building-entry fob), a card's chip generates a unique, one-time cryptogram with every tap that can't be reused. That's why real-time relaying, not simple data theft, is the essential feature of this malware.
The phone call itself functions as more than bait — it's the attacker's live control channel, letting them overcome hesitation, respond to confusion, and precisely coordinate the moments of app installation, card tap, and PIN entry.
This fits into a growing category of NFC relay fraud sometimes called "ghost tapping," following earlier malware families like NGate and SuperCard X. What makes this campaign distinct is pairing NFC relay capability directly with full remote-access malware.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




