A newly discovered Android malware, dubbed "WindRelay," enables criminals to capture and relay live bank card data in real-time, leveraging Near Field Communication (NFC) technology to facilitate contactless payments. This malware family, identified by researchers at Group-IB, allows attackers to intercept NFC activity on infected mobile devices and forward the data to a criminal-controlled device, which can then be used to make unauthorized transactions. The WindRelay malware exploits the proximity-based nature of NFC, effectively turning a victim's device into a relay station for illicit financial activity. This development raises concerns about the evolving threat landscape, as state-aligned threat actors may exploit such malware for geopolitical gain1. The implications of this malware extend beyond individual financial losses, highlighting the need for enhanced mobile security measures to mitigate the risk of NFC-based attacks, so what matters most to practitioners is the urgent need to implement robust defenses against this emerging threat.
New Android malware lets criminals use your bank card in real time
⚡ High Priority
Why This Matters
State-aligned threat activity raises the calculus from criminal to geopolitical — implications extend beyond the immediate target.
References
- Malwarebytes Labs. (2026, August 13). New Android malware lets criminals use your bank card in real time. *Malwarebytes*. https://www.malwarebytes.com/blog/mobile/2026/08/new-android-malware-lets-criminals-use-your-bank-card-in-real-time
Original Source
Malwarebytes Labs
Read original →