Android Malware DevilNFC Abuses Kiosk Mode For NFC Relay Fraud
ID: e4abcaba-85e2-5c22-b5f6-9fe90e76f7ad
STIX ID: report--e4abcaba-85e2-5c22-b5f6-9fe90e76f7ad
Feed Name: Cyber Press
Threat Score
This report describes two Android NFC relay malware families—DevilNFC and NFCMultiPay—that target banking customers in Europe and Latin America. It outlines their delivery via phishing (SMS/WhatsApp), use of fake banking updates and kiosk-mode to trap victims, interception and forwarding of OTPs to a Telegram bot, NFC relay and PIN capture (including Xposed-based host card emulation on rooted attacker devices), plus defanged C2 domains and IPs and evidence of AI-assisted development.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
