NFCShare is an Android banking trojan used in financially motivated campaigns that target mobile banking customers in Europe. First observed in early 2026 in lures impersonating Deutsche Bank, it later expanded to impersonate multiple banking and payment brands, particularly in Italy and Spain. The malware is typically delivered as a sideloaded malicious APK through phishing pages that mimic legitimate banking portals, shortened links, and fake app-update flows; some campaigns also use SMS messages or phone calls from fake bank representatives to guide victims through enabling installation from unknown sources.
Once installed, NFCShare presents a fraudulent card-verification interface designed to convince victims to place a payment card near the phone and enter the card PIN. It uses Android NFC functionality, including IsoDep and EMV-related commands, to read payment-card data from contactless cards. The malware then exfiltrates the stolen card information and PIN over a WebSocket-based command-and-control channel. The stolen data is intended for payment fraud, including NFC-enabled relay or tap-to-pay abuse.
Operationally, later NFCShare campaigns showed increased scale and discipline, including rapid rebuilding of APKs, rotation of impersonated banking brands, and hosting of payloads in public code repositories disguised as benign projects. Newer samples also used malformed APK packaging intended to disrupt automated extraction and analysis while preserving the malware’s core NFC theft and exfiltration logic. NFCShare has been discussed alongside other Android NFC-focused fraud malware families such as NGate, SuperCard X, and RelayNFC, but it has been assessed as a distinct family with its own code structure and implementation details. The activity is consistent with organized cybercriminal operations focused on banking and payment-card theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an example of Android NFC malware family.
Android banking trojan that impersonates banking apps, presents a fake card-verification interface, prompts victims to tap a payment card and enter its PIN, then exfiltrates NFC-derived payment card data and PINs over WebSocket C2 infrastructure.
Android malware distributed via phishing sites and fake banking APKs that steals banking credentials, payment card data via the phone’s NFC reader using EMV commands, and card PINs, then exfiltrates the data to attacker-controlled C2 infrastructure over WebSocket.
Android malware distributed via phishing sites and malicious APKs masquerading as banking app updates. It tricks victims into scanning payment cards over NFC, captures card number, type, expiry date, and a 4-digit PIN, and exfiltrates the data to a C2 server over WebSocket for use in NFC payment relay fraud.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.