New NGate Malware Uses AI To Masquerade As NFC Payment Apps
ID: dfa18270-6262-58e4-95b7-75b6ca52a867
STIX ID: report--dfa18270-6262-58e4-95b7-75b6ca52a867
Feed Name: Cyber Press
Threat Score
Researchers identified a NGate malware variant that injects malicious code into the HandyPay Android app to silently capture card PINs and relay NFC data, enabling contactless ATM cash-outs; the campaign has been active since November 2025, primarily targets users in Brazil, and relies on social-engineered sideloading via fake lottery and fake Play pages to install the trojanized app.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
