Cryptelio

Adoption

New Android Malware Exploits NFC Payments to Steal from Bank Accounts

Cryptelio Editorial Published 29 Sep 2026 · 15:45 UTC

Cybersecurity experts from Group-IB have discovered a new Android malware family known as WindRelay, which enables scammers to drain bank accounts and withdraw cash from ATMs without the victim's debit card. This malware captures live near-field communication (NFC) payment data and forwards it to attackers in real time.

The scam typically begins with a phone call from someone impersonating a bank worker, convincing the victim to install a malicious app. This app allows the scammer to take control of the victim's phone and install WindRelay. Once both the malicious app and WindRelay are on the device, the scammer can access the victim's banking app, arrange loans, and instruct the victim to tap their payment card against the phone while entering their PIN.

WindRelay transforms the phone into a fake contactless reader, streaming the tap data, including the one-time code from the card, to a device held against an ATM or store terminal. Group-IB reported that in one 13-minute call, the fraudster could take out a loan in the victim's name and stream their card data to a fake merchant terminal.

Researchers identified 23 samples of WindRelay uploaded to VirusTotal between November 2025 and July 2026, linking them to campaigns targeting bank customers in Czechia, Slovakia, and Slovenia, and connecting them to four command-and-control servers.

FAQ

What is WindRelay?

WindRelay is a new Android malware family discovered by cybersecurity experts that exploits NFC payments to steal from bank accounts and withdraw cash from ATMs without the victim's debit card.

How does the WindRelay malware operate?

The malware captures live NFC payment data and forwards it to attackers in real time. It typically starts with a scam phone call convincing the victim to install a malicious app, which allows the scammer to take control of the victim's phone.

What steps do scammers take to install WindRelay on a victim's phone?

Scammers impersonate bank workers to convince victims to install a malicious app. Once the app is installed, they can then install WindRelay on the device to access the victim's banking information.

What can scammers do once they have access to WindRelay?

Once WindRelay is installed, scammers can access the victim's banking app, arrange loans, and instruct the victim to tap their payment card against the phone while entering their PIN, allowing the scammer to capture sensitive data.

Where has WindRelay been reported to target victims?

WindRelay has been linked to campaigns targeting bank customers in Czechia, Slovakia, and Slovenia, with 23 samples identified between November 2025 and July 2026.

Read story →