Cybercriminals have developed a new Android malware that can turn victims smartphones into a bridge for stealing bank card information and carrying out contactless payment fraud, cybersecurity researchers have warned.

The malware, identified as WindRelay, operates in conjunction with a known remote-access trojan, SpyNote, to capture live information exchanged between a physical bank card and an Android phone via Near Field Communication (NFC).
NFC is the short-range technology that enables contactless payments when a bank card or smartphone is tapped against a payment terminal.
According to cybersecurity firm Group-IB, WindRelay was detected in the wild in August 2025 and has been used in a social-engineering scheme targeting victims in Czechia, Slovakia and Slovenia.
Meanwhile, the fraud begins with a phone call, text message or other communication in which criminals pretend to be bank officials.
The victim is persuaded to install an application, often personalised with the victim’s name, and once installed, SpyNote gives the criminal remote access to the phone and can silently install WindRelay, with the victim then tricked into placing a physical bank card against the infected smartphone, supposedly for identity verification, PIN change, or account resolution.
WindRelay reads the card’s NFC signals and sends the information in real time to another device controlled by the criminal, with such a device then imitating the victim’s card at a payment terminal or ATM, as the victim’s smartphone becomes a wireless bridge between the victim’s bank card and the criminal’s device.
Group-IB said it identified 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026, with the malware samples impersonating financial institutions in Czechia, Slovakia and Slovenia.
Meanwhile, the development adds to existing concerns over the use of mobile devices in cybercrime and financial fraud in Nigeria.
In June, the Nigeria Computer Emergency Response Team (ngCERT) issued an advisory on IPIDEA malware and malicious residential proxy networks, warning that the malware could hijack consumers internet connections and use compromised devices as part of criminal proxy networks.
While the ngCERT advisory concerns a different malware and attack method, both incidents highlight a growing risk: ordinary smartphones and connected devices can be secretly turned into tools for cybercriminals.
This is particularly relevant as Nigerians increasingly rely on smartphones for mobile banking, digital payments and other financial services.
Consequently, cybersecurity experts have advised users not to install applications sent through unsolicited calls, text messages or links, especially when the sender claims to represent a bank, as users should also be suspicious of requests to place payment cards against smartphones for supposed account verification.










