logo

NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs

ID: b6ae5e48-20d5-5813-a1d9-d49979e0b9ed

STIX ID: report--b6ae5e48-20d5-5813-a1d9-d49979e0b9ed

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-04-21

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

ESET researchers identified a new NGate Android malware iteration that trojanizes the HandyPay NFC app to capture contactless payment card data and PINs, enabling ATM cash-outs and unauthorized payments. The campaign, active since ~November 2025 and primarily targeting users in Brazil, distributes a poisoned HandyPay APK via fake lottery sites and social engineering; analysis suggests possible use of AI to generate or modify malicious code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.