logo

Ghost Tap Malware Fuels Surge in Remote NFC Payment Fraud

ID: 1b18f4d1-f181-58d1-b375-d8f236c9f5fe

STIX ID: report--1b18f4d1-f181-58d1-b375-d8f236c9f5fe

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

...
...

Group-IB researchers have documented a wave of Android tap-to-pay malware sold and promoted via Chinese-language Telegram cybercrime communities that remotely relays NFC card data from victims’ phones to complete fraudulent contactless transactions; researchers identified over 54 malicious APKs, named vendor groups (e.g., TX-NFC, X-NFC, NFU Pay), described smishing/vishing delivery methods, C2-enabled relaying and mule/mobile wallet cash-outs across multiple countries, and linked at least $355,000 in illegitimate transactions to one POS terminal vendor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.