Cyble Research and Intelligence Labs (CRIL) has identified a rapidly evolving NFC relay malware campaign targeting mobile payment users across Brazil.
The newly discovered malware family β named RelayNFC β turns a victimβs Android device into a remote card reader, enabling attackers to perform fraudulent contactless transactions as if the physical card were in their hands.
CRIL describes RelayNFC as βa lightweight yet highly evasive malware because of its Hermes-compiled payloadβ¦ enabling it to stealthily capture victimsβ card data and relay it in real time to an attacker-controlled server.β
Even more alarming: samples currently show zero detections on VirusTotal, indicating that security products are still blind to this threat.
CRILβs investigation reveals at least five phishing sites, all mimicking financial security portals and distributing the same malicious APK, indicating a coordinated operation. These include:
- hxxps://maisseguraca[.]site/
- hxxp://proseguro[.]site/
- hxxps://test.ikotech[.]online/
- hxxps://maisseguro[.]site/
- hxxp://maisprotecao[.]site/
According to the report, these fake pages lure victims using βsecure your cardβ messaging and then push the malware. CRIL notes: βDistribution relies entirely on phishing, tricking users into downloading RelayNFC malware.β
RelayNFC is unusual: itβs built in React Native, and its JavaScript code is compiled into Hermes bytecode, making reverse engineering far more difficult.
This modern mobile-app approach mirrors recent trends in Brazilian fintech-targeting malware such as Ngate and PhantomCard.
After installation, the malware spins up a phishing interface that instructs the user to tap their payment card against the phone which displays the Portuguese-language prompt βAPROXIME O CARTΓOβ (βbring the card closerβ).
CRIL confirms: βRelayNFC operates as a βreaderβ, enabling the malware to capture the victimβs card data and relay it to the attackerβs server.β The malware then asks for the victimβs PIN, which is harvested and forwarded to attackers.
RelayNFC sets up a persistent WebSocket channel to a command-and-control (C2) server, enabling a real-time APDU relay attack β the same technique used by advanced point-of-sale (POS) emulators and card-cloning operations.
The malware identifies itself as a βreaderβ during handshake:
Whenever attackers initiate a payment via their fraudulent POS emulator, the C2 server sends APDU commands like this
RelayNFC forwards the APDU to the victimβs NFC chip, receives the cardβs real response, and sends it back to the C2:
As CRIL explains: βThis real-time, bidirectional relayβ¦ enables the attacker to execute a full payment flow remotely, as if the victimβs card were physically present at their POS terminal.β
CRIL also uncovered a second sample, βcartao-seguro.apkβ, distributed via one of the same phishing sites. This version includes a RelayHostApduService component attempting to implement Host Card Emulation (HCE) β enabling the device to emulate a card itself rather than act as a reader. This suggests ongoing development and experimentation. As the report states: βA related variant attempts to implement Host Card Emulation (HCE), showing that the threat actor is exploring alternate NFC relay techniques.β
Brazil has long been a testing ground for financial malware, and RelayNFC represents the next escalation: real-time EMV transaction relays fully controlled via the victimβs device.
Related Posts:
- NFC Release 15 Unleashed: Quadruples Sensing Range, Revolutionizing Contactless Experiences
- Apple Breaks the Mold: iPhone NFC Opens to Third-Party Payments
- Microsoft Strengthens Default Security Posture Against NTLM Relay Attacks
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!