A newly discovered Android malware, dubbed "WindRelay," enables criminals to capture and relay live bank card data in real-time, leveraging Near Field Communication (NFC) technology to facilitate contactless payments. This malware family, identified by researchers at Group-IB, allows attackers to intercept NFC activity on infected mobile devices and forward the data to a criminal-controlled device, which can then be used to make unauthorized transactions. The WindRelay malware exploits the proximity-based nature of NFC, effectively turning a victim's device into a relay station for illicit financial activity. This development raises concerns about the evolving threat landscape, as state-aligned threat actors may exploit such malware for geopolitical gain1. The implications of this malware extend beyond individual financial losses, highlighting the need for enhanced mobile security measures to mitigate the risk of NFC-based attacks, so what matters most to practitioners is the urgent need to implement robust defenses against this emerging threat.