SuperCard X is an Android NFC fraud malware family and malware-as-a-service offering used to facilitate contactless payment and ATM fraud through real-time NFC relay. It is associated with the broader “ghost tapping” criminal ecosystem that abuses near-field communication to capture payment card data from a victim’s physical card and relay transaction data to an attacker-controlled device for fraudulent cash-out.
SuperCard X is characterized as a barebones kit disguised as a legitimate NFC-related application. In observed attack patterns, victims are socially engineered into installing the malicious Android app from unofficial sources, often under the pretense of banking, security, or payment-related verification. The victim is then instructed to tap a payment card against the infected phone, allowing the malware to capture contactless card data and relay transaction-specific information in real time. This enables fraudulent contactless purchases and, in some cases, cash withdrawals at ATMs that support contactless transactions. Public reporting places SuperCard X alongside related Android NFC malware families such as NGate, ZNFC, RelayNFC, PhantomCard, and other tooling derived from or inspired by NFC relay techniques.
Activity linked to SuperCard X was publicly identified in early 2025, including campaigns affecting banking customers in Italy, with later attempted deployments reported in Russia and Brazil. The malware has been discussed as part of a growing trend of commoditized Android NFC relay tooling sold or promoted in cybercrime communities, lowering the barrier to entry for financially motivated actors conducting payment-card fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another similar NFC relay malware family associated with ghost tapping-style fraud.
Named as an example of Android NFC malware family.
Referenced as Android malware involved in NFC payment relay schemes used to abuse stolen payment card data.
Previously documented Android NFC relay malware family referenced for comparison; noted as using an early and more detectable HCE approach with explicit financial AIDs declared in hce.xml.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.