Cybercriminals weaponize NFC relay malware with remote control software to drain payment card details in real time.
Security researchers have discovered a dangerous new threat targeting mobile phone users. Attackers are using a combination of two malicious programs working together—one that intercepts wireless payment signals and another that gives criminals remote control over infected devices. The result is a method to steal credit and debit card information directly from victims' phones and transmit it to attackers instantly.
Think of this like a pickpocket who has gained the ability to see through your wallet in real time and photograph every card as you use it. The attacker doesn't need to physically take your phone; they can watch and steal your payment details while you're making a purchase.
The threat combines two separate components. The first is called WindRelay—a form of malware designed specifically for Android phones that intercepts Near Field Communication (NFC) signals. NFC is the wireless technology that makes contactless payments possible—the invisible handshake between your phone and a payment terminal when you tap to buy something.
The second tool, known as SpyNote, is what criminals call a "remote administration tool." Basically, it turns your phone into a puppet that the attacker can control from anywhere in the world. They can see what's happening on your screen, access your files, and orchestrate the theft in real time.
When these two tools work together, they create a highly efficient theft operation. A criminal doesn't need to stand near you or intercept your payment in a traditional way. Instead, they infect your phone with this malware, and every time you make a contactless payment, they capture the card data and forward it to themselves instantly. It's like having an invisible middleman in every transaction you make.
The real-time component makes this particularly dangerous. Rather than stealing card information that might be flagged as fraud hours later, the attacker gets the details immediately and can begin using them before you've even left the store.
If your phone becomes infected with these programs, your financial security is at serious risk. Unlike traditional card theft where fraudulent charges might appear days later on your statement, this attack operates in the moment. Your card details are vulnerable every single time you use contactless payment.
The convergence of relay interception tools and remote control malware represents a new level of sophistication in mobile financial crime.
Additionally, this threat demonstrates how attackers continue to evolve their methods to exploit popular payment technologies. As more people rely on mobile wallets and contactless payment, criminals are adapting their strategies accordingly.
Staying informed about evolving threats is your best defense against becoming a victim.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →