logo

New payment-card scam involves a phone call, some malware and a personal tap

ID: 62f73d42-7fad-5394-9167-809cc29b4620

STIX ID: report--62f73d42-7fad-5394-9167-809cc29b4620

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2025-04-18

Date Updated: 2026-05-01

...
...

Cleafy describes an active scam in Italy where attackers use phishing SMS and social engineering to trick Android users into installing SuperCard X malware, then instruct victims to place their physical payment card near the infected phone so the malware can silently capture NFC-transmitted card details. The operation, overlapping with prior NGate activity and likely offered as malware-as-a-service by Chinese-speaking actors, enables near-instant theft of funds and may be replicable in other regions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.