NGate: NFC Relay Malware Enabling ATM Withdrawals Without Physical Cards
ID: 94ad1e68-cbb6-5a2f-93ba-d95d4f2ed31e
STIX ID: report--94ad1e68-cbb6-5a2f-93ba-d95d4f2ed31e
Feed Name: Zimperium Blog
Threat Score
CERT Polska uncovered NGate, a sophisticated Android malware campaign targeting Polish bank customers that abuses Android Host Card Emulation (HCE) and HostApduService to capture NFC payment exchanges and PINs via phishing-distributed fake banking apps; attackers relay the captured data to attacker-controlled devices at ATMs to perform unauthorized cash withdrawals, and vendors report on-device detection for known variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
