Analysis of NGate malware campaign (NFC relay)
ID: 230d9d64-5a1d-5539-a6d4-3e9612730654
STIX ID: report--230d9d64-5a1d-5539-a6d4-3e9612730654
Feed Name: CERT Polska
**CERT Polska analyzed NGate, an Android NFC-relay malware kit that—via phishing and bogus bank calls—tricks victims into sideloading an app which captures EMV card data and PINs (PAN, expiry, AIDs, APDUs) and exfiltrates them over a cleartext framed TCP protocol to a C2 (91.84.97.13:5653) so attackers can relay the session and withdraw cash from ATMs; the sample uses native code to XOR-decrypt config with the SHA-256 of the APK signing certificate and supports both reader (victim phone) and emitter (attacker phone/ATM) roles.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
