Ghost Tap is an NFC-enabled Android malware/fraud tooling cluster used to steal and relay payment card data for unauthorized contactless transactions and cash-out activity. Researchers describe it as a milestone in the evolution of NFC-based attacks and as a technique involving two Android components: a victim-side "Reader" app that captures card data when the victim taps a payment card to the infected phone, and a criminal-side "Tapper" app that emulates the victim’s card at a POS terminal or other payment endpoint. The malware is associated with Chinese-speaking cybercrime actors and vendors active in Telegram-based underground communities, with Group-IB naming TX-NFC, X-NFC, and NFU Pay among major vendors. Supporting reporting also notes Chinese debug strings and references to NFU Pay in related NFC-relay malware ecosystems.
Observed infection and distribution rely on social engineering. Victims are tricked via Telegram, messaging platforms, smishing, vishing, and fake or impersonating application lures into installing malicious APKs, sometimes disguised as legitimate apps or card-protection software. After installation, the malware prompts the victim to tap their bank or payment card to the phone under a pretext such as identity verification, payment-detail updates, or card protection. It then captures NFC/EMV card communications and relays or transmits the data to attacker-controlled infrastructure, enabling fraudsters to perform remote tap-to-pay purchases and potentially ATM or POS cash-outs as though the physical card were present.
The malware targets Android devices with NFC capability and focuses on payment-card theft and fraud. Reported behavior includes background monitoring for NFC card interactions, requesting NFC-related access, and transmitting stolen payment data to remote servers. One source further claims persistence and evasion features, including registering as a system service, hooking into Android’s NFC framework, and making removal difficult. Group-IB reported more than 54 distinct APK samples associated with Ghost Tap-related tooling and recorded at least $355,000 in fraudulent transactions tied to a single vendor between November 2024 and August 2025. The activity is global in scope, with victims and fraud cases reported across multiple countries, and with links to illicit POS-terminal suppliers advertising hardware from institutions across the Middle East, North Africa, and Asia.
High-confidence associations in the provided content include Chinese-linked threat actors/vendors, Telegram-based cybercrime distribution and sales channels, unauthorized contactless payment fraud, and use against banking/payment-card holders worldwide. No Ghost Tap-specific file hashes or package names were provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
NFC-enabled Android malware/tooling used to relay a victim’s card NFC communications over the internet so an attacker can emulate the card at a POS terminal and perform unauthorized tap-to-pay transactions and cash-outs remotely. Operates as two apps (“Reader” on victim device and “Tapper” on attacker device) working in tandem.
Ghost Tap is an Android malware that leverages NFC technology to intercept and steal payment card data when victims tap their cards against infected devices. It is distributed via social engineering, often through Telegram and other messaging platforms, and impersonates legitimate applications. The malware maintains persistence by registering as a system service and hooking into the Android NFC framework, making removal difficult.
NFC-relay malware/tool used by cybercriminals for cash-out operations by relaying payment card data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.