logo

New “Ghost Tap” Attack Hijacks Android Phones to Drain Bank Accounts

ID: a91827dd-24a4-5ea1-b644-3e90a2772664

STIX ID: report--a91827dd-24a4-5ea1-b644-3e90a2772664

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-09

Date Updated: 2026-05-22

Author: Mayura Kathir

...
...

Group-IB researchers uncovered the “Ghost Tap” ecosystem: NFC-enabled Android malware (reader+tapper apps) that captures ISO 14443 contactless card data and relays it via WebSocket C2 to attackers who cash out using fraudulent POS terminals and mule networks. The investigation identified 54+ APK samples, commercial malware vendors (TX-NFC, X-NFC, NFU Pay) selling subscriptions and custom builds, use of packers (360 Jiagu), reuse of NFCProxy code, at least $355,000 in fraudulent transactions tied to one operation, and multiple arrests across several countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.