Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The Xposed hook on HostEmulationManager.findSelectAid() solves this by intercepting the internal AID lookup before Android resolves it, remapping any incoming payment AID to DevilNFC's registered dummy identifier and forcing Android to route all subsequent APDU traffic into DevilNFC's relay pipeline.
“Features such as application sideloading, SMS access, accessibility services, browser customization, and NFC capabilities can be abused to steal credentials, intercept authentication codes, manipulate banking sessions, and facilitate contactless-payment fraud.”
“The victim is socially engineered into installing a fake banking or verification app.”
“DevilNFC can also use Android’s Kiosk Mode to trap the victim inside the fraudulent interface while the relay takes place.”
The Xposed hook on HostEmulationManager.findSelectAid() solves this by intercepting the internal AID lookup before Android resolves it, remapping any incoming payment AID to DevilNFC's registered dummy identifier and forcing Android to route all subsequent APDU traffic into DevilNFC's relay pipeline.
“The victim is socially engineered into installing a fake banking or verification app, placing their payment card against the phone, and entering the card’s PIN.”
A second form captures the online banking password through the same channel.
SmsPermissionManager silently polls incoming SMS messages in the background, intercepting any OTPs dispatched by the bank shortly after delivery and forwarding them to a dedicated C2 endpoint, which then routes them to the attacker's private Telegram channel in real time.
The Xposed hook on HostEmulationManager.findSelectAid() solves this by intercepting the internal AID lookup before Android resolves it, remapping any incoming payment AID to DevilNFC's registered dummy identifier and forcing Android to route all subsequent APDU traffic into DevilNFC's relay pipeline.
“The victim is socially engineered into installing a fake banking or verification app, placing their payment card against the phone, and entering the card’s PIN.”
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android-based banking-fraud malware that socially engineers victims into presenting their payment card and PIN to a fraudulent app, then relays live NFC card communications to an accomplice device at an ATM or payment terminal. It can use Android Kiosk Mode to keep the victim within the fraudulent interface during the relay.
Android malware that conducts NFC relay attacks against banking customers. It uses phishing via SMS or WhatsApp to deliver a fake banking security update, locks the victim device in Kiosk Mode, harvests card PINs, exfiltrates data to C2 and Telegram, and supports card relay for ATM withdrawals and chip-and-PIN transactions using a dual-role APK architecture.
Android NFC relay malware that uses phishing, kiosk mode, SMS interception, OTP theft, PIN harvesting, and a dual-role APK design. On victim devices it acts as a passive reader; on rooted attacker devices it becomes a host card emulator via Xposed and libnfcgate.so to relay APDU traffic for fraudulent chip-and-PIN transactions and ATM withdrawals.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.