logo

AI-Powered NGate Malware Evades Detection Inside NFC Payment Apps

ID: 1d941370-6fab-5c04-bbd5-8033564cb736

STIX ID: report--1d941370-6fab-5c04-bbd5-8033564cb736

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-21

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ESET Research identified a trojanized variant of HandyPay that contains NGate malware which intercepts NFC payloads and captures card data and PINs, relaying them to attacker-controlled devices for contactless fraud and ATM cash‑outs; distribution uses sideloaded APKs via a fake lottery site and spoofed Play-like pages targeting users in Brazil, with multiple IOCs and evidence of active exfiltration to a C2 server.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.