أخبار هاكرInternational Newsالأخبار

ESET NGate Malware Relays NFC Card Data to دفعات بدون اتصال then return inside a تطبيق مزيف

فكّر في البحث
تَعْملُ مِنْ نغيتِ و الكويكبِ مُغْطِلَة بيانات بطاقةِ دَفْع بدون اتصال من خلال a رقاقة هاتفِ نف ج
صورة لبطاقة الإئتمان المتوهجة قادمة من داخل هاتف ذكي (DreamStudio AI)

أول كتاب علني يعامل (ناغيت) كخدعة حشرية الموجة الثانية اختبأت داخل تطبيق الدفع وطلبت من الضحايا طباعة دبوسهم

ESET researcher Lukáš Štefanko named the family NGate because it turns one Android phone into a pipe for someone else’s contactless card. A victim with a non-rooted handset holds a credit or debit card to the back of the phone. The malware relays that NFC traffic to an attacker’s device, which then emulates the card at an NFC-capable ATM or terminal. The AEGIS Alliance is pairing this file with hardware badge research because both attacks live in the two inches between a chip and a reader. The 2024 paper was not the end of the family. In April 2026 the same researchers found a new build inside a trojanized copy of HandyPay, a legitimate NFC-relay app, aimed at Android users in Brazil and built to steal PINs as well as tap data.

كيف أصبحت أداة البحث مجموعة من الأدوات النقدية

NGate abused code from NFCGate, an open project that started at TU Darmstadt so academics could study NFC traffic. Research tools do not stay in labs. Criminal crews patched the idea into dropper apps and sent them at bank customers who had already been primed by phishing. The campaign against Czech clients started in November 2023. NGate itself showed up in samples in March 2024. Targets included customers of Raiffeisenbank and ČSOB. Czech police arrested a 22-year-old in March 2024 with 160,000 Czech koruna. ESET’s آب/أغسطس 2024 أطلق عليه أول برمجيات (أندرويد) مُلاحظة في البرية لإكمال تلك الشحنة

The victim phone does not need to be rooted. That is the detail banks keep underplaying. Host Card Emulation on modern Android is enough for the malware to register as a payment service, capture APDU traffic when a physical card is tapped against the handset, and ship that stream to a second device. The second device can be standing at an ATM a city away. Distance is a network problem, not a radio problem. The card never leaves the victim’s wallet. The money does.

Social engineering did the rest. Callers posed as bank security staff. They told customers a “protective” app would lock the card. They told them to tap the plastic on the phone “to verify.” Once the tap happened, the attacker had a live clone for as long as the session lasted. Contactless limits and offline-tap rules vary by issuer, which is why some cash-outs worked and some died at the terminal. The malware did not need every tap to work. It needed enough taps to pay for the kit.

بولندا، برازيل، وسوق لمجموعات إعادة الشحن

By late 2025 the technique was no longer a Czech novelty. CERT Polska described NGate-style relays against Polish bank customers, with HostApduService used to present stolen card data at ATMs. Zimperium and other mobile-threat vendors treated the family as a product line, not a one-off sample. Parallel kits sold as malware-as-a-service under names such as NFU Pay, TX-NFC, and PhantomCard. Brazil became a busy market because PIX culture and NFC cash-out both reward speed.

On April 21, 2026, ESET published the HandyPay chapter. أخذ المشغلون تطبيقاً حقيقياً كان يعرف بالفعل كيف يُنقل (إن إف سي)، وعالجوه، وشحنوا النتيجة من لعبة (غوغل) كـ(بروتيكو) و(ريو) الأمن said the extra code looked machine-written, complete with the emoji-laden log lines that large language models like to sprinkle into scripts. The campaign had been running since about November 2025. Four compromised devices in ESET’s telemetry sat in Brazil. Distribution sites impersonated card-protection pages and a lottery brand. A WhatsApp “you won” pitch pushed people toward the APK.

The HandyPay fork changed the economics. A monthly “donation” tier on the real app is cheap compared with renting a full malware-as-a-service panel. The patched build needed no exotic permissions beyond being set as the default payment app. Victims typed a PIN into a text box during the fake scan. That PIN left the phone over HTTP to a command server, separate from the NFC relay path. An attacker who has both the tap stream and the PIN is not limited to a single contactless ceiling. That is a different crime than the 2024 ATM trick, even if the family name stayed the same.

لماذا لا يتواصلون حتى لا

Banks spent a decade telling customers that tap-to-pay was safer than a magstripe. In a store, that is often true. The threat model assumed the card and the terminal were in the same room. NGate breaks the room. The terminal can be an attacker’s phone. The card can be in a kitchen in Prague or São Paulo. RFID-blocking sleeves do nothing once the owner is talked into tapping the card on their own handset. Play Protect helps against sloppy sideloads and does nothing for a user who installs a “bank security” APK and grants it payment defaults.

لقد غطي التحالف بالفعل ابن عم هذه المشكلة في الأجهزة FM11RF08Sرقائق مختلفة، نفس الدرس وقد صممت بروتوكولات التقريب من أجل الملاءمة. لم تكن مصممة لعالم حيث تكون نقطة نهاية واحدة غير واضحة تشمل ملفات الاحتيال والمحاسبة ذات الصلة تحذير بنك (فانتوم هاكر) و 700 Credit خرق كشف الملايين من مشتري السيارات- بيانات البطاقة قابلة لإعادة استخدامها. بمجرد أن يترك البلاستيك، البلاستيك لم يعد المحيط.

Issuers can lower tap limits, require online authorization, and kill a token after a single odd ATM. Those controls are uneven across countries and banks. A customer who has never heard of Host Card Emulation will still tap a card on a phone if a caller sounds like the fraud department. That is why the HandyPay lure worked. It looked like a wallet feature, not a crime tool.

ماذا يمكن للقراء أن يفعلوا دون انتظار رقعة

There is no vendor patch for a person who installs a fake wallet. Do not sideload payment apps from lottery pages, WhatsApp links, or “card protection” domains. Do not set an unknown app as the default payment service. Do not type a card PIN into any app that is not the official bank application downloaded from the Play Store. If a caller asks you to tap your card on your phone to “unlock” it, hang up and call the number on the back of the card. Google Play Protect should stay on. That is a floor, not a ceiling.

Banks that still treat NFC relays as a European curiosity are late. The 2024 Czech arrests proved the cash-out. The 2026 Brazilian samples proved the product can be restyled, translated, and sold with a PIN stealer attached. ESET published hashes and infrastructure on GitHub under its NGate IOC set. Defenders who only blocked last year’s package names will miss this year’s APK labels.

شاهدْ تحالفَ aegis أخبار هاكر و Tech News المكاتب، قرار اتهام مؤسس برقية في حالة أخرى حيث يتم التعامل مع تصميم أداة كجريمة إن جيت ليس من الناحية النظرية إنها مُؤخرة أفرغت الآلات النقدية، ثم عادت مرتديةً تطبيقاً للدفع.

المملكة المتحدة المتحالفة
جلب لكم الأخبار من المملكة المتحدة وأكبر أوروبا! Journalist, editor, activist, social media management, content creator. القائمة في المملكة المتحدة

ثانياً - الآثار المترتبة

القوات المسلحة

تم تصويره الحق في الحصول على موافقة *

ثانيا -
توقيع لأخبارنا و نشرات الأخبار

Newsletter Form

القوائم
ترابط وثيق