logo

DevilNFC Android Malware Uses Kiosk Mode to Trap Victims During NFC Relay Attacks

ID: ee83369c-0c8b-55ac-b743-12db2ba2c98b

STIX ID: report--ee83369c-0c8b-55ac-b743-12db2ba2c98b

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Tushar Subhra Dutta

...
...

analysts from Cleafy identified DevilNFC, an advanced Android banking malware that uses phishing-distributed apps to activate Android Kiosk Mode and perform NFC relay attacks—emulating cards and reading PINs by injecting a relay module into the NFC daemon—enabling unauthorized ATM and point-of-sale transactions; the report documents technical TTPs, AI-assisted development indicators, geographic targeting in Europe and LATAM, and provides IoCs including domains, IPs, MD5 hashes, and a package name.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.