Trojanized Android App Fuels New Wave of NFC Fraud
ID: 932fc798-b1f6-50c2-9276-addf3060b6ae
STIX ID: report--932fc798-b1f6-50c2-9276-addf3060b6ae
Feed Name: Infosecurity Magazine (News)
ESET researchers identified a new NGate campaign that modifies the HandyPay Android NFC app to stealthily capture payment card data and PINs, relaying them to attacker-controlled infrastructure to enable contactless fraud and ATM withdrawals; the trojanized app has been distributed via phishing since November 2025 and primarily targets users in Brazil, uses minimal permissions by leveraging default payment app behavior, and may include code partially generated with generative AI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
