logo

Chinese Hackers Deploy NFC-enabled Android Malware to Steal Payment Data

ID: d29cac99-e6eb-593f-85f3-df09f82d89c3

STIX ID: report--d29cac99-e6eb-593f-85f3-df09f82d89c3

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-01-07

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Chinese threat actors are operating a Ghost Tap campaign that distributes NFC-enabled Android malware via messaging platforms and fake apps to trick users into granting NFC permissions; once installed the malware silently reads payment card data when victims tap cards to infected devices, persists by registering as a system service and hooking Android’s NFC framework, and exfiltrates stolen data to attacker-controlled servers—researchers tracked over 54 samples and victims across multiple countries have reported financial losses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.