logo

New NGate Malware Uses AI To Masquerade As NFC Payment Apps

ID: dfa18270-6262-58e4-95b7-75b6ca52a867

STIX ID: report--dfa18270-6262-58e4-95b7-75b6ca52a867

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Varshini

...
...

Researchers identified a NGate malware variant that injects malicious code into the HandyPay Android app to silently capture card PINs and relay NFC data, enabling contactless ATM cash-outs; the campaign has been active since November 2025, primarily targets users in Brazil, and relies on social-engineered sideloading via fake lottery and fake Play pages to install the trojanized app.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.