logo

New NGate Android malware uses NFC chip to steal credit card data

ID: 5ee40bf0-d906-5988-bd4f-0ba385ab7c76

STIX ID: report--5ee40bf0-d906-5988-bd4f-0ba385ab7c76

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-08-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

NGate is an active Android malware campaign (observed since November 2023) that uses malicious PWAs/WebAPKs to phish victims into installing a payload which embeds an open-source NFC relaying tool (NFCGate). The malware captures NFC payment-card data and relays it to attackers, who obtain PINs via social-engineering calls and can perform contactless payments, ATM withdrawals, or clone NFC access tokens; ESET’s research and a Czech police arrest confirm real-world exploitation, and users are advised to disable NFC or only install apps from official sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.