Zimperium

WindRelay Combines NFC Relay Malware and Remote Access for Mobile Fraud

Written by Zimperium | Aug 27, 2026

A recent analysis reveals WindRelay, a new Android NFC relay malware deployed alongside the SpyNote remote access trojan to enable sophisticated mobile fraud. Attackers use live social engineering calls to convince victims to install a personalized RAT, then remotely deploy WindRelay without additional user interaction. The malware captures live NFC card data and relays it to attacker-controlled devices, enabling unauthorized purchases or withdrawals while remote access can facilitate additional financial fraud. The findings demonstrate how attackers are combining social engineering, device takeover, and NFC abuse into a single mobile attack chain.

Read the full report here.