logo

NGate Malware Enables Unauthorized Cash Withdrawals at ATMs Using Victims’ Payment Cards

ID: b0f6a0de-eea7-58e7-b09f-eae3ed09562e

STIX ID: report--b0f6a0de-eea7-58e7-b09f-eae3ed09562e

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2025-11-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

NGate is an Android malware campaign that leverages social engineering and a fake banking app to trick victims into tapping their payment card to a phone and entering their PIN; the malware registers as an HCE service, captures NFC exchanges and PINs, and relays them (via a plaintext TCP C2) to an attacker device or server to enable fraudulent ATM withdrawals. The report includes distribution methods, technical analysis of the relay/C2 protocol, mitigation advice, and IOCs (MD5 hashes, 91.84.97.13:5653, and a file-hosting URL).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.