A new malware family called WindRelay is being used with SpyNote Remote Access Trojan (RAT) to steal money through live NFC card-relay fraud This article explores nfc exchange attacker. . The operation combines phone-based social engineering, remote device control, and contactless payment abuse into a fast-moving attack.

The campaign demonstrates how fraudsters no longer need victims' physical cards; instead, they convince targets to tap their bank cards against an infected Android phone. WindRelay captures and relays the live NFC exchange to an attacker-controlled device, enabling fraudulent in-store payments or ATM withdrawals. This method involves placing malicious devices between real payment cards and legitimate terminals, transmitting transaction data in real time. The initial app was designed as SpyNote, a personalized Remote Access Tool (RAT) that displayed the victim's name instead of generic labels.

Once SpyNote was operational, the fraudster deployed WindRelay remotely. Following this, WindRelay was utilized to facilitate card-present fraud, thereby significantly increasing the financial damage before either the victim or the bank could react. WindRelay is specifically designed for NFC relay attacks, requiring permissions such as access to NFC communication and internet connectivity to transmit captured payment exchanges in real time.

An attacker's secondary device can present transactions to both real merchant terminals and ATMs while the victim’s physical card is still being authenticated.