NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs
ID: b6ae5e48-20d5-5813-a1d9-d49979e0b9ed
STIX ID: report--b6ae5e48-20d5-5813-a1d9-d49979e0b9ed
Feed Name: The Hacker News
Threat Score
ESET researchers identified a new NGate Android malware iteration that trojanizes the HandyPay NFC app to capture contactless payment card data and PINs, enabling ATM cash-outs and unauthorized payments. The campaign, active since ~November 2025 and primarily targeting users in Brazil, distributes a poisoned HandyPay APK via fake lottery sites and social engineering; analysis suggests possible use of AI to generate or modify malicious code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
