NGate Malware Enables Unauthorized Cash Withdrawals at ATMs Using Victims’ Payment Cards
ID: b0f6a0de-eea7-58e7-b09f-eae3ed09562e
STIX ID: report--b0f6a0de-eea7-58e7-b09f-eae3ed09562e
Feed Name: GBHackers
NGate is an Android malware campaign that leverages social engineering and a fake banking app to trick victims into tapping their payment card to a phone and entering their PIN; the malware registers as an HCE service, captures NFC exchanges and PINs, and relays them (via a plaintext TCP C2) to an attacker device or server to enable fraudulent ATM withdrawals. The report includes distribution methods, technical analysis of the relay/C2 protocol, mitigation advice, and IOCs (MD5 hashes, 91.84.97.13:5653, and a file-hosting URL).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
