logo

Massive surge of NFC relay malware steals Europeans’ credit cards

ID: d32e1db2-be6f-5a74-ab76-f1b47da377a4

STIX ID: report--d32e1db2-be6f-5a74-ab76-f1b47da377a4

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-30

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Researchers have observed a rapidly expanding NFC relay malware campaign targeting Android devices—more than 760 malicious apps and over 70 C2 servers—primarily in Eastern Europe, using Android HCE to capture or emulate EMV/APDU exchanges so attackers can authorize POS payments without the physical cardholder present; variants include EMV data exfiltration to Telegram, APDU relay toolkits, real-time "ghost-tap" payment manipulation, and fake payment/banking apps impersonating Google Pay or banks, and users are advised to avoid sideloading APKs, verify official bank app links, check NFC permissions, use Play Protect, and disable NFC if not needed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.