logo

NGate Android malware relays NFC traffic to steal cash

ID: 610e098f-128a-5efb-b47f-9a3cf7aad9b7

STIX ID: report--610e098f-128a-5efb-b47f-9a3cf7aad9b7

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2024-08-22

Date Updated: 2026-05-01

...
...

ESET researchers uncovered NGate, a novel Android crimeware campaign in Czechia that evolved from phishing PWAs/WebAPKs to an NGate malware family which leverages a misused NFCGate tool to relay NFC data from victims' physical payment cards to an attacker-controlled Android device; attackers used this to emulate cards and withdraw cash from ATMs, with fallback fund transfers. The report provides technical analysis, IoCs (samples, domains, IPs), MITRE ATT&CK mappings, victimology including arrests, and practical mitigations such as avoiding sideloading, disabling NFC when unused, and using mobile security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.