Many Android users store sensitive banking information on their devices, but a newly discovered cybercrime tactic shows how criminals can abuse NFC technology to turn a smartphone into a powerful tool for theft.

Security researchers have uncovered a new Android malware family known as WindRelay, designed specifically to intercept contactless payment information and send it to criminals in real time. Unlike traditional banking malware that focuses on stealing passwords or account details, this threat targets the communication between your bank card and your phone.

How the Attack Works

The scam usually begins with a phone call from someone pretending to be a representative from your bank. The caller creates a sense of urgency, warning about suspicious activity or claiming your account needs immediate protection. Victims are then instructed to download what appears to be a legitimate bank application. The app contains malicious software known as SpyNote, a remote access trojan that gives attackers control of the device. Once SpyNote is installed, attackers can secretly deploy a second malicious app called WindRelay. Together, these tools allow cybercriminals to remotely operate the phone while harvesting payment card information.

Why NFC is the Key

Near Field Communication (NFC) is the technology that powers contactless payments. It allows smartphones, payment cards, and terminals to exchange information when they are held close together. Criminals exploit this feature by convincing victims to tap their physical bank card against their infected phone. The malware immediately captures the NFC communication and relays it to a device controlled by the attacker elsewhere. This effectively allows criminals to use the victim’s card information in real time, even though the card never leaves the owner’s possession.

More Advanced Than Card Cloning

Modern bank cards don’t simply transmit static information. Every contactless payment generates a unique cryptographic code that can only be used once. Because of these security measures, attackers cannot simply record the details and replay them later. Instead, WindRelay acts as a live bridge, forwarding the transaction data instantly while the victim is interacting with their card. This real-time relay capability is what makes the attack particularly dangerous.

The Role of Social Engineering

Technology alone isn’t enough for the criminals to succeed.

The phone call is a critical part of the attack. Scammers stay on the line throughout the process, guiding victims step-by-step and overcoming doubts as they arise. By maintaining constant contact, they can coordinate key actions such as: Installing malicious software, Granting accessibility permissions, Opening banking applications and Entering a card PIN.

This combination of technical malware and psychological manipulation dramatically increases the success rate of the fraud.

A Growing Trend Called “Ghost Tapping”

Cybersecurity experts are seeing a rise in what has become known as ghost tapping attacks. Rather than stealing a physical card, criminals remotely use NFC relay technology to perform contactless transactions. WindRelay is the latest example in an expanding family of threats that exploit mobile devices and contactless payments. The addition of SpyNote’s remote access capabilities gives attackers even more control than previous NFC relay campaigns.

How to Stay Protected

Protecting yourself against these attacks largely comes down to caution and good security habits.

1. Be Wary of Unsolicited Calls – Banks rarely contact customers out of the blue demanding immediate action. If someone pressures you to act quickly, treat it as a warning sign.

2. Verify Before You Trust – If a caller claims to represent your bank, hang up and contact the institution directly using the phone number listed on its official website or on the back of your card.

3. Never Install Apps from Links – Legitimate banks do not ask customers to download security apps from text messages, emails, or third-party websites.

4. Avoid Sideloading Applications – Installing apps outside of the Google Play Store significantly increases your risk of downloading malware.

5. Think Twice About Permission – Accessibility permissions and device-control requests can give malware extensive control over a phone. Grant these permissions only when absolutely necessary and only to trusted applications.

6. Use Mobile Security Software – A reputable mobile security solution can help detect malicious applications before they gain control of your device.

Final Thoughts

The WindRelay malware campaign demonstrates how cybercriminals are evolving beyond traditional banking scams. Instead of stealing cards, they are using infected Android phones as a bridge between victims and payment systems in real time.

The good news is that these attacks still rely heavily on human interaction. Staying cautious, verifying unexpected requests, and only installing apps from trusted sources, remain some of the most effective ways to keep your bank cards and financial information safe.

This article has used information from Malwarebytes