logo

Tap-and-Steal: The Rise of NFC Relay Malware on Mobile Devices

ID: f8d4133f-8c40-520b-85fb-c4ba8fc2de92

STIX ID: report--f8d4133f-8c40-520b-85fb-c4ba8fc2de92

Feed Name: Zimperium Blog

Threat Score
78/100

Date Published: 2025-10-29

Date Updated: 2026-05-01

...
...

Since April 2024 zLabs identified a large-scale Android NFC/HCE relay malware campaign—over 760 malicious apps—masquerading as banks and payment services across multiple countries to steal EMV card data and enable fraudulent transactions; operators use 70+ C2 servers, Telegram bots/channels for exfiltration, websocket bidirectional control, and register malicious HCE services to intercept payment APDUs, with MITRE ATT&CK mappings and IOCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.