Security researchers have identified a surge in Android malware that abuses Near Field Communication (NFC) and Host Card Emulation (HCE) features to steal payment data and conduct fraudulent transactions. Since April 2024, over 760 malicious apps have been detected, with campaigns expanding from isolated incidents to a global threat affecting users in Russia, Poland, the Czech Republic, Slovakia, Brazil, and other countries. These apps impersonate trusted financial institutions and government services, including the Central Bank of Russia, Gosuslugi, Santander, and VTB Bank, to deceive users into installing them and setting them as the default payment method.
Once installed, the malware activates NFC relay functionality, capturing card data in real time and forwarding it to attacker-controlled servers. The operation is coordinated through more than 70 command-and-control servers and numerous Telegram bots, enabling attackers to use one infected device to collect payment data and another to complete fraudulent transactions at physical terminals. The rapid proliferation and sophistication of these attacks highlight the growing risk to mobile payment systems and the need for increased vigilance among Android users and financial institutions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Follow-up reporting characterized the campaign as a massive surge in NFC relay malware activity affecting Europeans' credit cards, reinforcing that the threat had expanded in scale and impact. This represented an escalation in public understanding of the scope of the activity.
Security reporting and research published in late October 2025 described a growing wave of Android NFC relay malware used to relay or clone tap-to-pay transactions and steal payment card data, with victims reported in Europe. The coverage framed the activity as an emerging mobile threat trend rather than a single isolated incident.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcezimperium.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.