logo

Android Malware DevilNFC Abuses Kiosk Mode For NFC Relay Fraud

ID: e4abcaba-85e2-5c22-b5f6-9fe90e76f7ad

STIX ID: report--e4abcaba-85e2-5c22-b5f6-9fe90e76f7ad

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Varshini

...
...

This report describes two Android NFC relay malware families—DevilNFC and NFCMultiPay—that target banking customers in Europe and Latin America. It outlines their delivery via phishing (SMS/WhatsApp), use of fake banking updates and kiosk-mode to trap victims, interception and forwarding of OTPs to a Telegram bot, NFC relay and PIN capture (including Xposed-based host card emulation on rooted attacker devices), plus defanged C2 domains and IPs and evidence of AI-assisted development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.