NGate Android malware relays NFC traffic to steal cash
ID: 610e098f-128a-5efb-b47f-9a3cf7aad9b7
STIX ID: report--610e098f-128a-5efb-b47f-9a3cf7aad9b7
Feed Name: WeLiveSecurity (ESET Research)
ESET researchers uncovered NGate, a novel Android crimeware campaign in Czechia that evolved from phishing PWAs/WebAPKs to an NGate malware family which leverages a misused NFCGate tool to relay NFC data from victims' physical payment cards to an attacker-controlled Android device; attackers used this to emulate cards and withdraw cash from ATMs, with fallback fund transfers. The report provides technical analysis, IoCs (samples, domains, IPs), MITRE ATT&CK mappings, victimology including arrests, and practical mitigations such as avoiding sideloading, disabling NFC when unused, and using mobile security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
