Chinese Hackers Use NFC-Enabled Android Malware to Steal Payment Information
ID: 4185fae4-a573-52a3-a8fa-f4e87d9435bc
STIX ID: report--4185fae4-a573-52a3-a8fa-f4e87d9435bc
Feed Name: GBHackers
Threat Score
Researchers at Group-IB uncovered an organized criminal operation (Ghost Tap / TX-NFC / NFU Pay) that distributes NFC-capable Android malware through Telegram channels as a subscription service; the malware relays contactless card data via a two-device NFC relay and C2 infrastructure, enabling global payment fraud across multiple countries and employing encryption, obfuscation, and anti-analysis techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
