NFCShare Android malware spreads via fake banking app updates on GitHub
ID: 03a76e94-4810-5560-8003-20e2e9815318
STIX ID: report--03a76e94-4810-5560-8003-20e2e9815318
Feed Name: Bleeping Computer
NFCShare is an active Android malware campaign distributing fake banking-app updates from a GitHub repository to phish users in Europe; it reads NFC EMV card data via Android's IsoDep, collects card details and a coerced 4-digit PIN, and exfiltrates the data over WebSocket. Researchers observed 56 unique malicious APKs impersonating multiple banks, social-engineering screens that prompt NFC scans, and evasion techniques (malformed ZIP/APK paths) aimed at disrupting automated analysis. Users are advised to install banking apps only from Google Play and enable Play Protect.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
