Ghost Tapped is a financially motivated Chinese cybercriminal operation centered on Android malware that abuses Near Field Communication functionality to facilitate payment-card fraud and direct theft from victims' bank accounts. The operation uses malicious Android applications masquerading as legitimate banking or payment software to socially engineer victims into installing the apps and presenting their payment cards to the device. The malware captures card data via NFC and relays it over attacker-controlled infrastructure to a separate criminal application used to emulate card-present transactions at point-of-sale terminals and, in some cases, cash-out activity. The operation has been observed using numerous app variants and a two-part architecture consisting of a victim-side reader component and an operator-side tapper component. Reported functionality includes collection of device identifiers and authentication-related data, network communications over WebSocket or MQTT, and remote coordination of fraudulent transactions. The campaign has affected victims globally and reflects a scalable model for remote NFC-enabled financial theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.