logo

Android malware turns phones into malicious tap-to-pay machines

ID: 9b415661-e56f-59bd-b9a7-1a6a496063c0

STIX ID: report--9b415661-e56f-59bd-b9a7-1a6a496063c0

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2025-04-24

Date Updated: 2026-04-28

...
...

SuperCard X is an Android NFC-based malware campaign that tricks victims (via smishing and phone social engineering) into installing an app which captures contactless payment card data when the victim taps their card to the infected phone; attackers receive the data and can use the attacker’s phone as a cloned card. The report notes the malware is distributed via a MaaS/affiliate model, shares code with prior projects (NGate/NFCGate), is engineered to minimize permissions to evade detection, and recommends skepticism of unsolicited messages, verifying contacts via official bank numbers, and refusing to install apps sent via text.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.