New NFC malware WindRelay also targets Czech accounts. It turns your phone into a payment card reader

  • Security firm Group-IB described new NFC malware WindRelay, which targets payment card holders
  • Attackers deploy it hand-in-hand with the SpyNote trojan and complete the entire fraud during a single phone call
  • Some of the intercepted samples impersonate Czech banks directly

Sdílejte:
Adam Kurfürst
Adam Kurfürst
15. 8. 2026 14:30
Advertisement

Analysts at Group-IB have described a previously unknown malware, WindRelay, which, in conjunction with the remotely controlled SpyNote trojan, can turn your phone into a live payment card reader. Among the 23 samples intercepted so far, there are also those that masquerade as Czech banks – and contactless fraud has a sad tradition in the Czech Republic.

It starts with a phone call, then they’ll want you to tap your card to your phone

It all starts with a phone call. The scammer impersonates a bank employee and, under the pretext that something is wrong with your card or account, convinces you to download a certain application outside the Google Play store. This application actually has access to Accessibility services – and that is the key to the whole trick. With it, according to Group-IB’s analysis, the attacker secretly installs WindRelay itself without a single click from you. No screen sharing is initiated, so you won’t notice anything.

To make the story more credible, the installation file is tailored specifically for you – it bears your name. Attackers obtain the victim’s name and phone number before the call. Another crucial moment comes when, under the pretext of identity verification or PIN change, they ask you to tap your physical payment card to the back of your own phone.

At that moment, your mobile phone becomes an intermediary between the card and the scammer. The malware reads card data via NFC and sends it in real-time to the attacker’s device, which could be located at the other end of the country. WindRelay uses two components for this: a reader in your phone that communicates with the card, and an emulator in the scammer’s phone that “pretends” to be the card at a payment terminal. Both parts exchange payment commands back and forth via their own server, so the transaction proceeds as if you were standing at the checkout yourself.

Two Scams in One Call

This method is dubbed Ghost Tap and has one significant advantage for thieves – they remain anonymous and can steal on a large scale. ESET already warned last year that attackers could theoretically operate entire “farms” of phones loaded with stolen cards, automatically sending fraudulent payments.

However, the combination of remote access and an NFC reader is particularly dangerous because the attacker profits twice over. Through the SpyNote trojan, they arrange a digital loan in your name, while simultaneously using NFC malware to pay with your card in stores. According to Group-IB, scammers manage both during a single, approximately thirteen-minute call – that is, before the bank or the victim even has time to react.

Czech Banks Are No Coincidence

The fact that WindRelay impersonates Czech, Slovak, and Slovenian financial institutions is no coincidence. Contactless NFC fraud is unfortunately prevalent here. Already in August 2024, ESET described the malware NGate, which similarly defrauded clients of three Czech banks and could withdraw cash from ATMs via phone.

And the numbers are growing. In the first four months of this year alone, ESET detected more NGate cases in the Czech Republic and Slovakia than in the entire last year – an approximate fifteen-fold increase year-on-year. Last October, the Czech National Bank (ČNB) also warned against a fraudulent application impersonating the Czech National Bank itself. Most attacks, according to experts, originate from a single organized group.

How to Defend Yourself?

You still have the upper hand against this threat. The entire scam hinges on the victim obediently doing what someone dictates over the phone. A few principles will protect you:

  • No bank will ever ask you to tap your card to your phone or dictate your PIN – if someone asks for this during a call, hang up
  • Do not install applications from SMS links or those dictated to you during a phone call; always find the bank and its application yourself
  • If the “bank” calls you saying your account is at risk, hang up and call back the official number (you can find it in your banking app, on the website, or on the back of your bank card)
  • Keep Google Play Protect enabled and only install sensitive applications from the official store
  • Get help – if you suspect something is wrong, consult with friends, family

Have you ever encountered a fraudulent call targeting your payment card?

Sources: Group-IB, The Hacker News, ESET

About the author

Adam Kurfürst

Adam studuje na gymnáziu a technologické žurnalistice se věnuje od svých 14 let. Pakliže pomineme jeho vášeň pro chytré telefony, tablety a příslušenství, rád se… More about the author

Adam Kurfürst
Sdílejte: