Skip to main content
Mallory
Back to malware
MalwareUsed by 1 actor

PhantomCard

PhantomCard is an Android NFC-relay banking trojan first identified by ThreatFabric. It is described as a China-origin NFC relay malware-as-a-service variant primarily targeting banking customers in Brazil, with reporting indicating it may be adaptable to other regions and potentially expand globally. The malware has been distributed via fake Google Play pages and masqueraded as a card-protection application named “Proteção Cartões” (“Card Protection”), including fabricated positive reviews to lure victims.

PhantomCard abuses near-field communication to conduct relay attacks against contactless payment cards, specifically EMV cards using ISO-DEP (ISO 14443-4) communications. It instructs victims to tap their payment card against the infected Android device and then prompts them to enter a 4-digit or 6-digit PIN. After detecting the card, the malware prepares and relays NFC card data through attacker-controlled infrastructure, establishing a communication channel between the victim’s physical card and a POS terminal or ATM near the fraudster, enabling fraudulent payments or cash-outs. Reported implementation details include use of the scuba_smartcards library for parsing payment-card data and the APDU command 00A404000E325041592E5359532E444446303100 to select the EMV Payment System Environment directory 2PAY.SYS.DDF01. Reporting also states the criminal operation requires a separate mule-side application to receive relayed data and communicate with the POS terminal.

ThreatFabric assessed that the actor advertising the malware as “Go1ano developer” was likely a reseller rather than the original developer. Supporting evidence included multiple Chinese debug strings in the code and references to “NFU Pay,” a Telegram-promoted NFC relay MaaS platform. ThreatFabric concluded that Go1ano developer likely purchased a customized version from NFU Pay and resold it. The malware’s C2 included an endpoint path “/baxi/b,” noted as corresponding to “Brazil” in Chinese, supporting assessment that the observed variant was tailored for the Brazilian market. Additional reporting places PhantomCard among a broader wave of NFC-enabled Android fraud tooling documented from 2024 to 2025.

High-confidence indicators of compromise reported by ThreatFabric include Android package com.nfupay.s145 with SHA-256 a78ab0c38fc97406727e48f0eb5a803b1edb9da4a39e613f013b3c5b4736262f, and package com.rc888.baxi.English with SHA-256 cb10953f39723427d697d06550fae2a330d7fff8fc42e034821e4a4c55f5a667.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Go1ano developer

In this report we introduce PhantomCard - a new Android NFC-based Trojan targeting banking customers in Brazil and potentially expanding globally.

via threatfabricthreatfabric.com
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

In this campaign, PhantomCard masquerades as “Proteção Cartões” (“Card Protection”) application and is distributed via fake Google Play pages... the page also contains fake positive reviews that help to convince victims into installing the malware.

T1566.002Spearphishing LinkEvidence1

Los señuelos se distribuyen mediante enlaces maliciosos que redirigen a páginas de inicio de sesión falsas...

Execution

1 technique
T1204.002Malicious FileEvidence1

PhantomCard se distribuye a través de páginas web maliciosas que se hacen pasar por aplicaciones legítimas...

Stealth

1 technique
T1036MasqueradingEvidence3

PhantomCard masquerades as “Proteção Cartões” (“Card Protection”) application... PhantomCard is delivered via fake “Google Play” web-pages mimicking apps for “card protection”.

Credential Access

2 techniques
T1557Adversary-in-the-MiddleEvidence1

PhantomCard enables relay attacks by obtaining NFC data from a victim's banking card and transmitting it to a threat actor's device to perform transactions at point-of-sale (POS) systems or ATMs.

T1649Steal or Forge Authentication CertificatesEvidence2

As a next step, PhantomCard will request PIN code to provide it to fraudster to authenticate the transaction (if needed): 'Enter your password. For security reasons, enter your 4-digit password to confirm verification.'

Collection

1 technique
T1557Adversary-in-the-MiddleEvidence1

PhantomCard enables relay attacks by obtaining NFC data from a victim's banking card and transmitting it to a threat actor's device to perform transactions at point-of-sale (POS) systems or ATMs.

Command and Control

1 technique
T1071Application Layer ProtocolEvidence1

The data is transmitted via the NFC relay server under criminals’ control... One of the endpoints on the Command-and-Control (C2) server of PhantomCard is '/baxi/b'.

INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
2 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.