ESET researchers reported an NGate malware campaign targeting Android users in Brazil through a trojanized version of the legitimate HandyPay NFC relay app. Active since November 2025, the operation distributes malicious APKs via a fake Rio de Prêmios lottery site that redirects victims through WhatsApp and through counterfeit Google Play pages promoting an app called Proteção Cartão. After installation, the app prompts victims to set it as the default NFC payment app, captures card PINs, and harvests payment card data for relay to attacker-controlled infrastructure.
The stolen NFC data can be used to provision virtual cards for fraudulent contactless purchases and NFC-enabled ATM withdrawals. ESET said this variant differs from earlier NGate activity by abusing HandyPay’s built-in NFC transfer features instead of the open-source NFCGate tool, a change researchers believe improves stealth and lowers operational cost. The two observed samples were linked to the same threat actor through shared infrastructure and the same modified HandyPay build, while unusual emoji-filled code suggested possible GenAI-assisted development, though ESET said that remains unconfirmed. Google was notified through the App Defense Alliance, HandyPay’s developer opened an internal investigation, and Google Play Protect is reported to detect and block the latest variant.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
ESET reported the campaign to Google through the App Defense Alliance and notified the HandyPay developer. The developer said an internal investigation was underway, and Google Play Protect was reported to detect and block the latest NGate variant.
Researchers connected two NGate samples to the same actor based on shared infrastructure and use of the same modified HandyPay application. ESET also noted code characteristics that may indicate generative AI assistance, though it said this was not proven.
Once installed, the trojanized app prompted victims to set it as the default NFC payment app, then captured payment card data and card PINs. The stolen NFC data was relayed to attacker-controlled infrastructure for fraudulent contactless purchases and ATM withdrawals.
The threat actor used a fake Rio de Prêmios lottery website that redirected victims through WhatsApp, as well as a fake Google Play-style page offering the malware as Proteção Cartão. These lures delivered malicious APKs to victims' Android devices.
ESET said the NFC-based payment fraud campaign using a new NGate malware variant has been active since November 2025. The operation targeted Android users in Brazil with malware embedded in a trojanized version of the legitimate HandyPay app.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.