logo

Trojanized Android App Fuels New Wave of NFC Fraud

ID: 932fc798-b1f6-50c2-9276-addf3060b6ae

STIX ID: report--932fc798-b1f6-50c2-9276-addf3060b6ae

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2026-04-21

Date Updated: 2026-04-22

...
...

ESET researchers identified a new NGate campaign that modifies the HandyPay Android NFC app to stealthily capture payment card data and PINs, relaying them to attacker-controlled infrastructure to enable contactless fraud and ATM withdrawals; the trojanized app has been distributed via phishing since November 2025 and primarily targets users in Brazil, uses minimal permissions by leveraging default payment app behavior, and may include code partially generated with generative AI.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.