Researchers at Group-IB have identified a new Android malware family that captures contactless bank card data and relays it to criminals in real time, ScamTelegraph reports. The malware, named WindRelay, was deployed alongside a remote access Trojan in an attack that began with a 13-minute phone call from someone impersonating the victim's bank.
Near Field Communication is the wireless technology that lets smartphones, payment cards and payment terminals communicate at very short range. Rather than stealing a physical card, the attackers capture NFC activity on an infected phone and forward it instantly to a criminal-controlled device held against a contactless payment terminal or an ATM that supports contactless withdrawals.
The attack described by researchers unfolded in stages. During the call, the victim was persuaded to install an Android app carrying the bank's name. That app was SpyNote, a remote access Trojan, which handed the attacker control of the phone and allowed the quiet installation of a second app, WindRelay. The attackers then opened the victim's legitimate banking app remotely and arranged a loan in the victim's name, while asking the victim to tap their physical payment card against the phone and enter its PIN.
The division of labor between the two pieces of malware is the notable development. SpyNote gets the attackers inside the device, while WindRelay converts the victim's physical card into an instrument criminals can use somewhere else at that exact moment.
Timing is central because of how contactless payments are secured. Some NFC signals produce a static code that can simply be copied. Sophisticated contactless payment cards do not work that way: each tap generates a unique, one-time cryptogram that cannot be reused. Relaying that data live is the only way to make it useful, which is why real-time transmission is the defining feature of this malware category.
The phone call is not merely the lure. It functions as the attackers' control channel, letting them overcome hesitation, answer confusion instantly, and coordinate the precise moments at which the victim installs an app, taps a card and enters a PIN.
The technique sits within an established and expanding category of NFC relay fraud sometimes described as ghost tapping, following earlier families such as NGate and SuperCard X. The combination with SpyNote is what distinguishes this campaign. Malwarebytes for Android detects the two components as Android/Trojan.NGate.ACRBCF9BBC3C1 and Android/Trojan.NGate.ACR2401245FC5.
What is NFC relay fraud?
It is a technique in which malware on a victim's phone captures the data produced when a contactless card is tapped and transmits it live to a criminal's device, which presents it at a payment terminal or ATM elsewhere. Because payment cards generate single-use cryptograms, the relay must happen in real time to work.
Why would a bank never ask a customer to tap their card against their phone?
There is no legitimate verification process that requires a customer to tap a payment card against a handset and enter a PIN at the instruction of a caller. That sequence exists only to harvest the card's contactless data and its PIN.
How did the attackers get the malware onto the device?
Through social engineering during a phone call, not a technical exploit. The victim was convinced to sideload an app labelled with the bank's name, which then installed the second component without further interaction.
What practical steps reduce the risk?
Avoid sideloading apps from outside the Google Play store, treat unexpected requests for Accessibility or device-control permissions as a serious warning sign, and never act on an unsolicited call without independently verifying it using the official number on a card or statement. Running an up-to-date real-time anti-malware product on the device adds a further layer.
According to Malwarebytes, the original report is available at https://www.malwarebytes.com/blog/mobile/2026/08/new-android-malware-lets-criminals-use-your-bank-card-in-real-time.
