Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

NFCGate

NFCGate is a legitimate open-source Android NFC research tool created in 2015 by students at the Technical University of Darmstadt for analyzing and debugging NFC traffic. It has since been widely abused by cybercriminals as the basis for Android banking malware and fraud tooling that relays or emulates payment-card NFC data to steal funds.

The documented malicious use centers on NFC-enabled banking fraud. Attackers distribute modified NFCGate builds, often via phishing websites, WhatsApp, Telegram, or apps masquerading as legitimate banking, e-government, security, or contactless-payment software. Victims are socially engineered to install the app, grant NFC and network access, and in some cases accessibility permissions. In the common attack flow, victims are instructed to tap their bank card against the infected phone and enter their PIN during a fake authorization process. The malware captures card data via NFC and sends it to attacker-controlled infrastructure, allowing criminals to emulate the victim’s card on another device and perform contactless purchases or withdraw cash from ATMs without the physical card. A newer “reverse NFCGate” scheme tricks the victim into setting the malicious app as the default contactless payment app so the phone emulates an attacker-controlled card at an ATM; the victim is then told to tap the phone on the ATM reader and use a supplied PIN.

The content links NFCGate abuse to banking fraud campaigns in the Czech Republic, Russia, and Italy, with attempted deployments also reported in Brazil. ESET described a Czech campaign in August 2024 using phishing sites to spread malicious NFCGate mods. Russian authorities said criminals distributed NFC malware disguised as bank software via WhatsApp and Telegram, and that victims across nearly all of Russia were affected. Russian police reported dismantling a criminal enterprise using NFCGate-based malware, with preliminary losses exceeding 200 million rubles, while Russian security company F6 estimated that various NFCGate-based strains had stolen at least 1.6 billion rubles from Russian customers by the end of 2025.

The content also notes that modified NFCGate has been bundled with other Android malware, including SpyNote as a dropper/NFC activator and CraxsRAT in later bundles. Related campaigns and variants mentioned include SuperCard and RatOn. By early 2025, analysts had reportedly identified more than 80 unique malware samples built on the NFCGate framework. High-confidence indicators and behaviors directly described include Android apps disguised as bank or payment software, requests for NFC/internet and sometimes accessibility permissions, instructions to tap a payment card to the phone, collection of card PINs, relay of NFC data to attacker-controlled servers, and use of harvested credentials for ATM withdrawals or contactless fraud.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

2 distinct techniques documented for this family, organized by ATT&CK tactic.

Credential Access

1 technique
T1557Adversary-in-the-MiddleEvidence1

In the earlier versions, the malware used an open-source tool called NFCGate to capture, relay, and replay the payment card information.

Collection

2 techniques
T1005Data from Local SystemEvidence1

NGate was originally documented in mid-2024 and steals payment card information through the mobile device's near-field communication (NFC) chip.

T1557Adversary-in-the-MiddleEvidence1

In the earlier versions, the malware used an open-source tool called NFCGate to capture, relay, and replay the payment card information.

ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

kaspersky blogNews
Jan 13, 2026
Direct and reverse NFC relay attacks being used to steal money | Kaspersky official blog

Originally an open-source NFC traffic analysis/debugging tool (2015) that was later modified by criminals into an NFC relay framework enabling real-time (and later delayed/offline) relaying/emulation of payment card NFC data to facilitate fraudulent ATM withdrawals and POS payments, often paired with social engineering and sometimes Accessibility abuse.

Read more
the hacker newsNews
Dec 11, 2025
ThreatsDay Bulletin: Spyware Alerts, Mirai Strikes, Docker Leaks, ValleyRAT Rootkit - and 20 More Stories

Legitimate open-source NFC tool abused as a base for NFC-relay style banking fraud malware; used to harvest card data/enable ATM cash-outs by relaying NFC interactions after victims install fake banking apps and are socially engineered to tap their card and enter PIN.

Read more
the record mediaNews
Dec 8, 2025
Russian police bust bank-account hacking gang that used NFCGate-based malware

A legitimate open-source NFC relay tool that is being abused as the core component of financial-theft mobile malware to relay/emulate victims’ bank cards and enable unauthorized ATM withdrawals.

Read more
the hacker newsNews
May 5, 2025
⚡ Weekly Recap: Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain Backdoors

Legitimate NFC traffic tool repurposed as Android malware to relay NFC data and enable ATM/payment fraud; includes a 'reverse NFCGate' technique to route drop-card data to victim devices.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping2

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.