A new Android malware known as NGate has been identified targeting mobile devices to steal cash from ATMs by relaying EMV card data and PINs from victims' phones. The malware leverages NFC capabilities to intercept sensitive payment information, which is then used to facilitate unauthorized ATM withdrawals. Security researchers have highlighted the technical sophistication of NGate, which can bypass traditional security controls by exploiting the contactless payment features on compromised devices.
Reports indicate that NGate is distributed through malicious APKs and is part of a broader trend of mobile malware targeting financial transactions. The malware's ability to relay EMV data and PINs poses a significant threat to both individual users and financial institutions, as it enables attackers to perform real-time fraudulent cash withdrawals. Security experts recommend heightened vigilance for suspicious mobile applications and urge users to monitor their devices for signs of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC's weekly mobile security and malware roundup for the first week of November 2025 listed NGate among covered Android and NFC-related malware topics. The provided reference does not add specific new incident details beyond confirming NGate as an active subject of mobile threat reporting.
A Security Online article described NGate malware as stealing cash from ATMs by relaying EMV card data and PINs from a victim's phone over NFC. The report framed the activity as an Android-based mobile malware threat enabling ATM cash-out fraud.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.