logo

RelayNFC Targets Brazil

ID: fb59dbf0-92b5-586e-a711-58f20513db2c

STIX ID: report--fb59dbf0-92b5-586e-a711-58f20513db2c

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2026-06-09

Date Updated: 2026-07-17

...
...

## Executive Summary Cyble Research and Intelligence Labs discovered RelayNFC, an active Android malware campaign targeting Brazilian users that uses phishing pages to trick victims into installing an app which either reads NFC cards or emulates them, then relays APDU commands and responses over persistent WebSockets to enable remote EMV payment fraud; the samples use React Native with Hermes bytecode to hinder analysis, show zero VirusTotal detections, and include IOCs such as APK SHA-256 hashes, phishing URLs, and C2 IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.