logo

Chinese Hackers Use NFC-Enabled Android Malware to Steal Payment Information

ID: 4185fae4-a573-52a3-a8fa-f4e87d9435bc

STIX ID: report--4185fae4-a573-52a3-a8fa-f4e87d9435bc

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-07

Date Updated: 2026-05-08

Author: Mayura Kathir

...
...

Researchers at Group-IB uncovered an organized criminal operation (Ghost Tap / TX-NFC / NFU Pay) that distributes NFC-capable Android malware through Telegram channels as a subscription service; the malware relays contactless card data via a two-device NFC relay and C2 infrastructure, enabling global payment fraud across multiple countries and employing encryption, obfuscation, and anti-analysis techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.