New variants of NFCShare are targeting mobile banking customers across Europe through phishing sites and GitHub-hosted fake banking app updates that impersonate legitimate banks. Researchers said the campaign, first seen spoofing Deutsche Bank, has expanded to primarily target banking brands in Italy and Spain, with victims lured into installing malicious APKs after being told to enable apps from unknown sources or follow fake bank update prompts.
Once installed, the malware abuses a phone’s NFC capability to trick victims into scanning their payment cards and entering their PINs, then exfiltrates the stolen card data and PINs to attacker-controlled infrastructure over WebSocket for potential NFC payment relay fraud. Investigators also reported that newer samples are rebuilt rapidly and use malformed APK packaging, including broken ZIP paths, to disrupt automated analysis and slow detection while preserving recognizable behaviors such as combined WebView and NFC activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that newer NFCShare samples use malformed ZIP paths inside APK files to disrupt some automated analysis tools and delay detection. This packaging change was noted as part of the newer wave of samples tied to the expanded campaign.
D3Lab first observed and documented the NFCShare Android malware in January 2026, when it was impersonating Deutsche Bank. The malware targeted banking users by stealing payment card data via NFC and capturing card PINs.
Around 2026-05-14, researchers observed the NFCShare campaign broaden beyond its earlier Deutsche Bank focus to impersonate multiple banking brands, primarily in Italy and Spain. The expansion also included GitHub-hosted fake banking app updates and more rapid APK rebuilding by the operators.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
rhisac.org
Open sourcecybersecuritynews.com
Open sourced3lab.net
Open sourcebleepingcomputer.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.