New Android fraud campaign exploits contactless payments within 13 minutes

Researchers reveal WindRelay, a rapidly escalating Android fraud scheme that combines social engineering and malware to hijack contactless payments in under 15 minutes, highlighting the increasing sophistication of mobile payment threats.

Researchers say a new Android fraud campaign has shown how quickly a social-engineering call can escalate into live payment theft. Group-IB said the operation, dubbed WindRelay, began with fake bank support calls and could move from first contact to contactless card abuse in around 13 minutes, a sign of how mobile malware is increasingly being fused with payment systems rather than used for simple data theft. TechRadar reported that the campaign has been active since late 2025 and has already hit victims in several central and eastern European countries.

According to Group-IB, the attackers relied on highly personalised vishing, or voice phishing, using details about the target to make the call sound credible. Victims were persuaded to install a malicious Android app that was a customised version of SpyNote, a remote-access trojan that gave the criminals control of the handset after the user sideloaded it and granted accessibility permissions. Once that foothold was established, the second-stage WindRelay malware could be installed and used to handle the payment fraud separately from the device takeover.

The scheme did not stop at stealing card data. Group-IB said the attackers also used the compromised phones to take out loans in victims’ names, while the NFC component was used to carry out live contactless transactions after the victim was instructed to tap a payment card to the phone. That combination of account takeover, device compromise and payment abuse is what makes WindRelay stand out: it links several already-known fraud techniques into a single operation rather than introducing a wholly new one.

Security researchers say the wider threat is growing fast. Kaspersky has described similar NFC relay attacks in which malicious apps trick users into tapping bank cards to their phones so card data can be relayed to criminals in real time, while D3Lab has separately documented NFCShare, another Android banking trojan that mimics legitimate bank verification screens to capture card information and PINs. Other reports have also shown SpyNote being repurposed in campaigns beyond banking, including crypto theft and fake public-alert lures, underlining how adaptable the malware has become.

For users, the warning signs are relatively simple. Google advises installing apps only from Google Play and treating sideloaded software as risky, particularly when it comes from a caller claiming to be from a bank. A real bank employee should not need to ask a customer to install software from outside the official store, grant accessibility access, or tap a payment card to a phone in order to resolve a support issue.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.