logo

NFC-Powered Android Malware Enables Instant Cash-Outs

ID: ab9a5d16-8b07-552d-b1e9-ad748d6404d8

STIX ID: report--ab9a5d16-8b07-552d-b1e9-ad748d6404d8

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-04-24

Date Updated: 2026-04-21

Author: Alexander Culafi, Senior News Writer, Dark Reading

...
...

Researchers from Cleafy identified 'SuperCard X', a Chinese-speaking MaaS Android malware that hides inside seemingly benign apps and uses an NFC-relay technique to capture victims' contactless card data and relay it in real time to attacker-controlled devices; attackers then perform immediate contactless payments or ATM withdrawals. The campaign leverages social-engineering via SMS/WhatsApp, requests minimal Android permissions to evade AV detection, includes published IoCs, and has been observed targeting Italy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.