logo

New NGate Malware Developed Using AI Hides in NFC Payment Apps

ID: 271ad6d4-2b5f-52d8-86d7-13667d0c84b8

STIX ID: report--271ad6d4-2b5f-52d8-86d7-13667d0c84b8

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A trojanized HandyPay Android NFC relay app is being distributed outside Google Play and contains a new NGate variant that silently captures NFC payment card data and user PINs, exfiltrating them to an attacker-controlled C2 to enable contactless payments and ATM cash-outs; distribution channels include a fake Brazilian lottery site and impersonated Play Store pages, the campaign targets users in Brazil and shows signs of AI-assisted code generation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.