# Android malware and NFC relay fraud campaigns

> Live situation record from CLSTR: https://clstr.news/situations/android-malware-and-nfc-relay-fraud-campaigns
> Updated: 2026-09-03T16:45:40.000Z. Sources: 2. Developments: 2.

Security researchers have identified sophisticated Android malware campaigns targeting users through social engineering and remote access tools. 

Initial findings detailed a scheme involving the SpyNote remote access trojan (RAT) and WindRelay, a specialized NFC malware. In this campaign, attackers use vishing—posing as bank employees—to trick victims in Eastern European countries, such as the Czech Republic, Slovakia, and Slovenia, into sideloading a malicious APK. Once Accessibility Service permissions are granted, attackers can control banking apps to apply for loans or execute NFC relay attacks. These attacks allow criminals to capture real-time NFC communication when a victim taps their physical credit card against the compromised phone, enabling unauthorized purchases at point-of-sale terminals.

Subsequent reports expanded on these threats, identifying additional malware and distribution methods. A second campaign involving the StreamRat malware spreads via paid advertisements on social media platforms like Facebook, Instagram, and TikTok, often promising free streaming services. This campaign has reportedly reached approximately 570,000 users. Additionally, the WindTapper group continues to utilize phone scams and WindRelay malware to facilitate real-time unauthorized contactless payments.

## Timeline

### 2026-09-03: Android malware campaigns target users via social media and phone scams

New Android malware campaigns, including StreamRat and WindRelay, are targeting users via social media ads and phone scams to steal credentials and facilitate contactless payment fraud.

2 sources. https://clstr.news/cluster/android-malware-campaigns-target-users-via-social-media-and-phone-scams

### 2026-08-13: WindRelay malware turns Android phones into fraudulent payment devices

A sophisticated malware campaign uses SpyNote and WindRelay to turn Android phones into fraudulent POS devices, enabling attackers to steal loans and relay NFC credit card data in real-time.

4 sources. https://clstr.news/cluster/windrelay-malware-turns-android-phones-into-fraudulent-payment-devices

---
Cite as: Android malware and NFC relay fraud campaigns. CLSTR, https://clstr.news/situations/android-malware-and-nfc-relay-fraud-campaigns
