NFC relay malware is a category of malicious mobile applications observed targeting mobile devices. According to the provided content, these apps abuse near-field communication (NFC) and host card emulation (HCE) functionality to obtain payment data from infected devices and enable fraudulent transactions. Zimperium reported a surge in this activity and stated that more than 760 malicious NFC relay applications have been observed in the wild. The content identifies mobile devices as the target platform and payment data as the primary objective. No specific threat actor, malware family name, industry targeting beyond payment fraud, or concrete indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
NFC Relay Malware targets mobile devices to intercept and relay Near Field Communication (NFC) transactions, potentially enabling theft or fraud.
Malware targeting mobile devices that abuses NFC and host card emulation to steal payment data and perform fraudulent transactions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.