Researchers have identified a surge in Android malware abusing Near-Field Communication (NFC) and Host Card Emulation (HCE) to steal payment data and facilitate unauthorized transactions. Over 760 malicious apps have been discovered targeting banks, payment services, and government portals worldwide, including institutions in Russia, Europe, and Brazil. These apps often impersonate trusted organizations, urging users to set them as default NFC payment handlers, and exfiltrate sensitive EMV card data—such as device IDs, card numbers, and expiry dates—via Telegram channels. Attackers remotely control the apps through command-and-control servers, enabling them to relay card terminal requests, provide PINs, and execute fraudulent transactions with minimal user interaction. The rapid adoption of "Tap-to-Pay" has made NFC a lucrative target, with over 70 C2 servers and dozens of Telegram bots coordinating attacks against more than 20 global institutions since April 2024.
CERT Polska has specifically analyzed the NGate malware campaign, which employs NFC relay attacks to enable unauthorized ATM withdrawals using victims’ own payment cards. Victims are lured through phishing messages and social engineering phone calls, convincing them to install a malicious Android app and verify their payment card by tapping it against their phone and entering their PIN. The app captures the NFC exchanges and PIN, relaying this data to an attacker-controlled device at an ATM, allowing criminals to withdraw cash without physical access to the card. The malware registers itself as an HCE payment service and conceals its C2 infrastructure within encrypted assets, complicating detection and response efforts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Further reporting described Android malware stealing both payment card details and victims' PINs to support near-immediate ATM withdrawals, reinforcing the operational model seen in NFC relay attacks. The report highlighted the practical fraud impact of these mobile banking and payment theft techniques.
Public reporting warned that misuse of Android NFC and Host Card Emulation for payment-data theft was increasing, using NGate as a key example of how mobile malware can facilitate card fraud. The coverage emphasized the growing threat of apps that weaponize legitimate Android payment-related features.
Researchers and incident responders documented the NGate campaign's techniques, including relaying NFC payment data from victims' phones to attacker-controlled devices at ATMs. Their analysis linked the activity to financially motivated fraud focused on stealing card data and enabling immediate withdrawals.
A malware campaign dubbed NGate began targeting Android users in the Czech Republic, using malicious apps to abuse NFC and Host Card Emulation features to relay payment card data for fraudulent cash withdrawals. The operation relied on social engineering to trick victims into installing the apps and disclosing card PINs.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.