NFC tap-to-pay gets tapped by hackers

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A new variant of the NGate Android malware has been embedded into the legitimate HandyPay NFC relay app to steal contactless payment card data and PINs. Distributed via a fake lottery site and a spoofed Google Play page targeting Brazilian users since November 2025, the trojanized app relays NFC data to attackers for contactless fraud and ATM cash-outs. ESET researchers suspect generative AI was used in development, evidenced by emoji markers in debug logs. The attack requires victims to sideload the app outside Google Play, bypassing Android's built-in install warnings.

3m read timeFrom csoonline.com
Post cover image

Sort: