logo

New NGate variant hides in a trojanized NFC payment app

ID: 10ca7909-f206-59cc-a9fd-47047a62f2e7

STIX ID: report--10ca7909-f206-59cc-a9fd-47047a62f2e7

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
72/100

Date Published: 2026-04-21

Date Updated: 2026-05-01

...
...

ESET Research identified an active NGate campaign that trojanized the HandyPay Android NFC relay app to capture and relay victims' payment card data and PINs for contactless ATM cash-outs and unauthorized payments in Brazil; distribution used a fake Rio de Prêmios lottery site and a fake Google Play page, with IoCs (sample hashes, domain protecaocartao.online, C2 IP 108.165.230.223) published and analysis of tactics and likely GenAI-assisted code changes included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.