NGate NFC malware targets Android users through trojanized payment app
ID: 9ee8ff84-d54f-59fe-92ef-e22ed01ae380
STIX ID: report--9ee8ff84-d54f-59fe-92ef-e22ed01ae380
Feed Name: Help Net Security
Threat Score
ESET Research identified an active Brazil-focused campaign (since November 2025) that trojanizes the HandyPay NFC payment app with a new NGate malware variant to relay contactless card data and exfiltrate PINs to an attacker C2; distribution uses a rigged lottery website and a fake Google Play page, enabling contactless transactions and ATM withdrawals with stolen credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
