Hacker NewsInternational NewsNews

NGate’s HandyPay Clone and a 13-Minute WindRelay Call Show How NFC Relays Empty Contactless Cards

Unmasking NGate | ESET Research

The expensive kits rent for hundreds of dollars a month. The cheap one hid inside a payment app that asked for a donation. A later one did not even wait for the victim to install the relay.

ESET researcher Lukáš Štefanko named a malware family NGate because it turns one Android phone into a pipe for someone else’s contactless card. The victim holds a debit or credit card against the back of a handset that does not need to be rooted. The malware captures the NFC exchange and relays it to an attacker’s device, which then emulates the card at a terminal or an NFC-capable ATM. The AEGIS Alliance is treating the 2024 Czech cash-outs as the origin story, not the whole market. By the spring and summer of 2026, the same idea had a price list, a Brazilian disguise, a measured surge in blocked attacks, and a cousin kit that a caller could plant during a thirteen-minute phone call.

A lab tool, then a Czech cash-out

NGate borrowed from NFCGate, an open project that began at TU Darmstadt so researchers could study NFC traffic. Academic code does not stay in the paper. Criminal crews folded the idea into dropper apps and aimed them at bank customers who had already been softened by phishing. The campaign against Czech clients started in November 2023. NGate samples showed up in March 2024. Targets included customers of Raiffeisenbank and ČSOB. Czech police arrested a 22-year-old that March with 160,000 Czech koruna. ESET’s August 2024 paper called it the first Android malware observed in the wild to finish that relay and turn it into cash.

Host Card Emulation is the detail banks still underplay. Modern Android can let an app register as a payment service, read the APDU traffic when a physical card is tapped on the phone, and ship that stream across the internet. The second device can be standing at an ATM in another city. Distance is a network problem, not a radio problem. The plastic never leaves the victim’s wallet. The money does. Callers posed as bank staff and told people a “protective” app would lock the card if they tapped the plastic “to verify.” Contactless ceilings and online-authorization rules vary by issuer, which is why some taps died at the terminal and some did not. The kit did not need every tap. It needed enough of them to pay for itself.

HandyPay was chosen because it was cheap

By late 2025, CERT Polska was describing NGate-style relays against Polish customers, with HostApduService used to present stolen card data at ATMs. Parallel kits were sold as malware-as-a-service under names such as NFU Pay, TX-NFC, and PhantomCard. ESET later put numbers on the shopping decision. NFU Pay advertised at almost $400 a month. TX-NFC was around $500. HandyPay, a legitimate NFC-relay app that has been on Google Play since 2021, asked for a €9.99 monthly donation, if it asked for anything. It also needed no exotic permissions beyond being set as the default payment app. That is why the operators patched HandyPay instead of renting a full panel.

On April 21, 2026, ESET published the chapter. The campaign had been running since about November 2025 and was aimed at Android users in Brazil. The trojanized builds shipped off the real Play Store as PROTECAO_CARTAO.apk and Rio_de_Prêmios_Pagamento.apk, pushed through a fake card-protection page and a fake lottery site for Rio de Prêmios, including a WhatsApp “you won” pitch. Both sites sat on the same domain. WeLiveSecurity said the added code looked machine-written, down to emoji-stuffed log lines. Victims typed a PIN into a text box during a fake scan. That PIN left over plain HTTP to a command server, separate from the NFC path, so the attackers were not limited to a single contactless ceiling. ESET’s telemetry on the command server showed four compromised devices, all in Brazil, with captured PINs, IP addresses, and timestamps. The malicious HandyPay build was never on the official store.

The blocked-attack count, then a thirteen-minute call

Kaspersky’s telemetry, published June 1, 2026, put a scale on the category rather than on one family. From January through April 2026 its products blocked 35,600 Android attacks that used NFC techniques, including SuperCard X, PhantomCard, NGate, and other malicious modifications of NFCGate. That was a 188 percent increase from just over 12,300 blocks in the same four months of 2025. The company said users in Russia hit these lures most often, with Latin America and Europe close behind. Chief security expert Sergey Golovanov drew a line between “direct NFC,” where the victim is talked into tapping a card on an infected phone, and a newer “reverse NFC” pattern in which the victim is steered into sending money themselves. Direct relay is the NGate pattern. It is no longer a Czech footnote.

On August 12, 2026, Group-IB documented a related but distinct family it named WindRelay, deployed beside a SpyNote remote-access trojan. In the investigated case, a caller pretending to be the bank talked a victim through installing a sideloaded app during a call that lasted about thirteen minutes. SpyNote then let the fraudster install WindRelay without a second consent ritual and without turning on screen sharing. The victim was told to tap the physical card and enter a PIN. WindRelay streamed the live NFC exchange to a criminal device at a terminal. The same remote access was used to open a loan inside the victim’s real banking app. Group-IB linked 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026, with lures impersonating institutions in Czechia, Slovakia, and Slovenia, plus four command addresses. Malwarebytes later said its Android product detected the pair under NGate-family names, which is a detection label, not proof that the code is Štefanko’s original sample.

The room the banks assumed

Tap-to-pay is often safer than a magstripe at a shop counter. The old threat model assumed the card and the reader were in the same room, held by the person who owns the card. NGate and WindRelay break the room. The reader can be a second phone. The card can be in a kitchen in Prague or São Paulo. An RFID sleeve does nothing once the owner is persuaded to tap the plastic on their own handset. Play Protect helps against sloppy sideloads. It does not help a person who installs a “bank” APK from a caller and sets it as the default wallet.

The AEGIS Alliance has already covered the hardware cousin of this problem in the FM11RF08S hotel-badge backdoor. Different chips, same lesson: proximity was built for convenience. Related money-movement files include the Phantom Hacker bank-drain warning, the 700Credit breach, and the proxy network Google said it had disrupted. Card data is reusable once it leaves the plastic.

There is no vendor patch for a person who installs a fake wallet. Do not sideload payment apps from lottery pages, WhatsApp links, or a caller who will not let you hang up. Do not set an unknown app as the default payment service. Do not type a card PIN into anything except the bank’s own application from the official store. If someone asks you to tap your card on your phone to “unlock” it, hang up and call the number printed on the card, from a different phone if you can. Issuers can lower tap limits, force online authorization, and kill a token after one odd ATM. Those controls are uneven. A customer who has never heard of Host Card Emulation will still tap if the voice sounds like the fraud department.

Defenders who blocked only the 2024 package names will miss PROTECAO_CARTAO, the lottery APK, and whatever label WindRelay wears next month. ESET published hashes for the NGate sets. Group-IB published the thirteen-minute chain. The economics are the part worth remembering: a €9.99 relay app, patched with code that looks machine-written, plus a trojan that installs the next relay for you. See Hacker News and Tech News, and the Telegram founder case, for another fight over what a tool’s design is allowed to do. This one already emptied cash machines.

The AEGIS Alliance U.K.
Bringing you news from the United Kingdom and greater Europe! Journalist, editor, activist, social media management, content creator. Based in the U.K.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button