logo

NGate Android malware uses HandyPay NFC app to steal card data

ID: fcca07d9-6f5d-52d9-89d2-de37a6f57a3d

STIX ID: report--fcca07d9-6f5d-52d9-89d2-de37a6f57a3d

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Bill Toulas

...
...

ESET researchers report a new NGate Android variant that steals NFC payment card data by using a trojanized HandyPay app; attackers distribute fake APKs and social-engineered pages to get victims to set the app as the default NFC payment handler, collect card PINs and NFC reads, and exfiltrate data to a hardcoded email—campaign active since November 2025 and primarily targeting Android users in Brazil.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.