logo

NGate: NFC Relay Malware Enabling ATM Withdrawals Without Physical Cards

ID: 94ad1e68-cbb6-5a2f-93ba-d95d4f2ed31e

STIX ID: report--94ad1e68-cbb6-5a2f-93ba-d95d4f2ed31e

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2025-11-12

Date Updated: 2026-05-01

...
...

CERT Polska uncovered NGate, a sophisticated Android malware campaign targeting Polish bank customers that abuses Android Host Card Emulation (HCE) and HostApduService to capture NFC payment exchanges and PINs via phishing-distributed fake banking apps; attackers relay the captured data to attacker-controlled devices at ATMs to perform unauthorized cash withdrawals, and vendors report on-device detection for known variants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.