According to ESET telemetry, threat actors keep finding new ways to exploit #NFC technology: detections surged by 78% compared to H1 2025; however, overall numbers remain low.
#NGate has demonstrated its relevance and is now enhanced with contact-stealing functionality. ESET researchers believe that this feature is designed to lay the groundwork for future attacks.
An NGate-based malware adapted for Brazil, #PhantomCard, targets banking clients via fake #Android apps that claim to improve security and privacy, distributed on pages featuring fabricated positive reviews.
And #RatOn combines RAT-like features with relay functionality, showcasing the determination of threat actors to evolve the methods of compromise. It’s distributed via fraudulent ads and apps, with the language targeting Czech and Slovak users.
Attackers remain faithful to tried-and-tested methods like #phishing calls and messages, while increasingly relying on psychological manipulation and #social engineering rather than exploiting just the technological aspect of NFC.
Read more about the evolution of NFC threat landscape in the latest #ESETThreatReport https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h22025.pdf

Two days ago, the #NewYork Sheriffs’ Office warned about Android #NGate malware.

It can steal (relay) your card details & PIN, letting threat actor withdraw cash via ATMs—without your card.
It abuses #NFC tech used for tap-to-pay.

ESETresearch identified an active campaign distributing #NGate – Android NFC relay malware used for contactless payment fraud – targeting Brazilian users.
It is available for download via fake Google Play sites mimicking 4 major banks and 1 e-commerce app.
It shares the same package name (com.billy.cardemv) as some #NGate / #PhantomCard variants targeting Brazil, suggesting it could be a new version still focused on Brazil.
#ngate captures NFC card data and relays it to an attacker-controlled device, which uses the data for ATM withdrawals or POS payments—all without physical access to the victim’s card. We described #NGate in details in our blogpost in 2024
https://www.welivesecurity.com/en/eset-research/ngate-android-malware-relays-nfc-traffic-to-steal-cash/
IoCs:
Android/Spy.NGate.BD
223D7AA925549C9C657C017F06CF7C19595C2CEE
5a341dc1-98f9-4264-859a-e8bc6d236024-00-1vfeomyys26m9.janeway.replit[.]dev
googleplay-santander.pages[.]dev
googleplay-bb.pages[.]dev
googleplay-itau.pages[.]dev
googleplay-mercadolivre.pages[.]dev
googleplay-bradesco.pages[.]dev
Pagamenti NFC minacciati dal malware NGate

Una nuova ondata di attacchi informatici colpisce i pagamenti NFC: l'evoluzione del malware NGate, i pericoli reali e come mettere in sicurezza lo smartphone.

Gomoot : tecnologia e lifestyle Scopri le ultime novità in fatto di hardware, tecnologia IA e altro

#BREAKING #ESETresearch NFC Android malware impersonates banking app in 🇵🇱 Poland. #NGate malware impersonates a banking verification application to steal NFC data and PIN from victims’ physical payment card. x.com/LukasStefanko

TThe threat actor can then use it to withdraw money from ATM via contactless terminal without having payment card.

More information about NGate malware: https://www.welivesecurity.com/en/eset-research/ngate-android-malware-relays-nfc-traffic-to-steal-cash/

IoCs:
C&C: 38.180.222[.]230:5577
Sample: 6A41008744498A3EDDA0BDF763ADC7F157441E1D
Detection name: Android/Spy.NGate.L

NGate Android malware relays NFC traffic to steal cash

ESET Research uncovers Android malware that relays NFC data from victims’ payment cards, via victims’ mobile phones, to the device of a perpetrator waiting at an ATM.

Pour pirater votre smartphone, les hackers ont deux nouvelles stratégies ultra redoutables

Les cybercriminels innovent constamment pour tromper les utilisateurs de smartphones. En ce moment, les hackers s’appuient sur deux nouvelles tactiques pour pirater les smartphones Android et les i…

[ White and Hack ]
NFC-Malware kopiert Bankkarten​ | heise online
https://heise.de/-9848256 #Cybercrime #Malware #NGate #NFC #nfcgate
NFC-Malware leert Bankkonten

Phishing und Malware kombiniert ein Angreifer, um Geldautomaten Bankkarten vorzuspielen und per NFC Geld abzuheben. Beobachtet wurde das in Tschechien.​

heise online
NGate Android malware relays NFC traffic to steal cash

ESET Research uncovers Android malware that relays NFC data from victims’ payment cards, via victims’ mobile phones, to the device of a perpetrator waiting at an ATM.

NGate: O nouă amenințare pentru utilizatorii Android - TECHNEWSRO

Cercetătorii ESET au făcut o descoperire alarmantă care afectează utilizatorii de dispozitive Android. Un nou tip de malware, numit NGate, a fost identificat ca având capacitatea unică de a intercepta și de a redirecționa traficul NFC (Near Field Communication) pentru a fura fonduri din conturile bancare ale victimelor direct de la ATM-uri.NGate reprezintă o combinație

TECHNEWSRO - Pasionat de tehnologie
📬 NGate: Neue Android-Malware, die NFC-Daten abgreift
#Malware #Smartphones #NFC #NFCGate #NGate #Phishing #TUDarmstadt https://sc.tarnkappe.info/02a47d
NGate: Neue Android-Malware, die NFC-Daten abgreift

Mit Hilfe von Phishing: Die Android-Malware NGate greift NFC-Daten von Zahlungskarten ab und leitet sie an Cyberkriminelle weiter.

Tarnkappe.info