RelayNFC Targets Brazil
ID: fb59dbf0-92b5-586e-a711-58f20513db2c
STIX ID: report--fb59dbf0-92b5-586e-a711-58f20513db2c
Feed Name: Cyble Blog
## Executive Summary Cyble Research and Intelligence Labs discovered RelayNFC, an active Android malware campaign targeting Brazilian users that uses phishing pages to trick victims into installing an app which either reads NFC cards or emulates them, then relays APDU commands and responses over persistent WebSockets to enable remote EMV payment fraud; the samples use React Native with Hermes bytecode to hinder analysis, show zero VirusTotal detections, and include IOCs such as APK SHA-256 hashes, phishing URLs, and C2 IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
