NGate is an Android malware family used in NFC relay fraud against banking customers. It is designed to capture or relay contactless payment card data from a victim’s physical card through an infected Android device and enable unauthorized contactless purchases or ATM cash withdrawals. The malware has been associated with campaigns targeting users in Europe, including Poland and the Czech Republic, and later Brazil.
Early NGate activity was built around code derived from the NFCGate research project and was distributed through bank-impersonation lures. Victims were socially engineered into installing a malicious Android application outside the official app store, then instructed to place a payment card near the phone and enter the card PIN under the pretense of verification or security checks. The malware relayed NFC communication in real time to attacker-controlled infrastructure, a requirement for abusing dynamic transaction data used in contactless payments. In these campaigns, the malicious apps also included functionality to collect and transmit the victim’s PIN.
Later variants evolved to abuse trojanized legitimate NFC relay software rather than relying solely on NFCGate-derived tooling. A notable NGate variant embedded malicious code into the legitimate Android app HandyPay and targeted users in Brazil. This version was distributed via fake lottery-themed websites, spoofed app-store pages, and WhatsApp-guided social engineering. After installation, it asked to be set as the default payment application, prompted the victim to enter a payment card PIN, and instructed the victim to tap the physical card to the device. The malware then forwarded NFC payment data to an attacker-controlled device and exfiltrated the PIN, enabling fraudulent payments and contactless ATM withdrawals.
NGate is widely characterized as Android NFC relay malware and has also been described as an Android banker in some reporting because of its direct role in financial theft. It is part of a broader trend of mobile malware families abusing NFC for payment fraud, alongside families such as SuperCard X, RelayNFC, and related threats. Reporting has also noted signs that some newer NGate code may have been generated or modified with AI assistance, although definitive proof of that development method is not available.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The functionality for entering and transmitting the PIN alongside the NFC stream was added to the original project.
Further analysis reveals the logic of how NFC interface data is streamed to an internet connection.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a similar NFC relay malware family in the broader ghost tapping fraud category.
Named as an example of Android NFC malware family.
Named in the malware/tools list as another malware/tool associated with the Telegram malware ecosystem.
Referenced as Android malware involved in NFC payment relay schemes used to abuse stolen payment card data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.