Hacker NewsInternationale nyhederNyheder

Name

Unmasking NGate between 124; ESET Research
Illustration of NGate Android malware cloning contactless payment card data through a smartphone NFC chip
En teal glødende kreditkort billede kommer fra inde fra en smartphone. (DreamStudio AI)

Den første offentlige skrift-up behandlet NGate som en tjekkisk ATM trick. Den anden bølge gemte sig i en betalingsapp og bad ofrene skrive deres PIN-fil

ESET researcher Lukáš Štefanko named the family NGate because it turns one Android phone into a pipe for someone else’s contactless card. A victim with a non-rooted handset holds a credit or debit card to the back of the phone. The malware relays that NFC traffic to an attacker’s device, which then emulates the card at an NFC-capable ATM or terminal. AEGIS Alliance is pairing this file with hardware badge research because both attacks live in the two inches between a chip and a reader. The 2024 paper was not the end of the family. In April 2026 the same researchers found a new build inside a trojanized copy of HandyPay, a legitimate NFC-relay app, aimed at Android users in Brazil and built to steal PINs as well as tap data.

Hvordan en forskning værktøj blev en cash- out kit

NGate abused code from NFCGate, an open project that started at TU Darmstadt so academics could study NFC traffic. Research tools do not stay in labs. Criminal crews patched the idea into dropper apps and sent them at bank customers who had already been primed by phishing. The campaign against Czech clients started in November 2023. NGate itself showed up in samples in March 2024. Targets included customers of Raiffeisenbank and ČSOB. Czech police arrested a 22-year-old in March 2024 with 160,000 Czech koruna. ESET’s August 2024 papir kaldte det den første Android-malware observeret i naturen for at fuldføre dette relæ.

The victim phone does not need to be rooted. That is the detail banks keep underplaying. Host Card Emulation on modern Android is enough for the malware to register as a payment service, capture APDU traffic when a physical card is tapped against the handset, and ship that stream to a second device. The second device can be standing at an ATM a city away. Distance is a network problem, not a radio problem. The card never leaves the victim’s wallet. The money does.

Social engineering did the rest. Callers posed as bank security staff. They told customers a “protective” app would lock the card. They told them to tap the plastic on the phone “to verify.” Once the tap happened, the attacker had a live clone for as long as the session lasted. Contactless limits and offline-tap rules vary by issuer, which is why some cash-outs worked and some died at the terminal. The malware did not need every tap to work. It needed enough taps to pay for the kit.

Polen, Brazil og et marked for relæsæt

By late 2025 the technique was no longer a Czech novelty. CERT Polska described NGate-style relays against Polish bank customers, with HostApduService used to present stolen card data at ATMs. Zimperium and other mobile-threat vendors treated the family as a product line, not a one-off sample. Parallel kits sold as malware-as-a-service under names such as NFU Pay, TX-NFC, and PhantomCard. Brazil became a busy market because PIX culture and NFC cash-out both reward speed.

Den 21. april 2026 udgav ESET HandyPay kapitlet. Operatører tog en reel app, der allerede vidste, hvordan man relæer NFC, lappet det, og afsendt resultatet fra Google Play som SPECIAO _ CARTAO.apk og Rio _ de _ Prêmios _ Pagamento.apk. WeLiveSecurity said the extra code looked machine-written, complete with the emoji-laden log lines that large language models like to sprinkle into scripts. The campaign had been running since about November 2025. Four compromised devices in ESET’s telemetry sat in Brazil. Distribution sites impersonated card-protection pages and a lottery brand. A WhatsApp “you won” pitch pushed people toward the APK.

The HandyPay fork changed the economics. A monthly “donation” tier on the real app is cheap compared with renting a full malware-as-a-service panel. The patched build needed no exotic permissions beyond being set as the default payment app. Victims typed a PIN into a text box during the fake scan. That PIN left the phone over HTTP to a command server, separate from the NFC relay path. An attacker who has both the tap stream and the PIN is not limited to a single contactless ceiling. That is a different crime than the 2024 ATM trick, even if the family name stayed the same.

Hvorfor kontaktløs stadig ser sikker indtil det ikke

Banks spent a decade telling customers that tap-to-pay was safer than a magstripe. In a store, that is often true. The threat model assumed the card and the terminal were in the same room. NGate breaks the room. The terminal can be an attacker’s phone. The card can be in a kitchen in Prague or São Paulo. RFID-blocking sleeves do nothing once the owner is talked into tapping the card on their own handset. Play Protect helps against sloppy sideloads and does nothing for a user who installs a “bank security” APK and grants it payment defaults.

AEGIS Alliance har allerede dækket hardware fætter til dette problem i FM11RF08S hotelskilt bagdørForskellige chips, samme lektion. Nærhedsprotokoller blev designet for nemheds skyld. De var ikke designet til en verden, hvor et endpoint er malware. I forbindelse med svig og regnskabsovertagelsessager indgår bl.a.: Fantomhacker bank- drain advarsel og 700Kreditbrud, der afslørede millioner af bilkøbere. Kortdata kan genbruges. Når den forlader plastikken, er plastikken ikke længere omkredsen.

Issuers can lower tap limits, require online authorization, and kill a token after a single odd ATM. Those controls are uneven across countries and banks. A customer who has never heard of Host Card Emulation will still tap a card on a phone if a caller sounds like the fraud department. That is why the HandyPay lure worked. It looked like a wallet feature, not a crime tool.

Hvad læsere kan gøre uden at vente på et plaster

There is no vendor patch for a person who installs a fake wallet. Do not sideload payment apps from lottery pages, WhatsApp links, or “card protection” domains. Do not set an unknown app as the default payment service. Do not type a card PIN into any app that is not the official bank application downloaded from the Play Store. If a caller asks you to tap your card on your phone to “unlock” it, hang up and call the number on the back of the card. Google Play Protect should stay on. That is a floor, not a ceiling.

Banks that still treat NFC relays as a European curiosity are late. The 2024 Czech arrests proved the cash-out. The 2026 Brazilian samples proved the product can be restyled, translated, and sold with a PIN stealer attached. ESET published hashes and infrastructure on GitHub under its NGate IOC set. Defenders who only blocked last year’s package names will miss this year’s APK labels.

Se menighedens alliance Hacker News og Tech News bordene og Telegrams grundlægger tiltale i en anden sag, hvor et redskabs design behandles som forbrydelsen. NGate er ikke en teoretisk demo. Det er et relæ, der allerede tømt pengeautomater, derefter kom tilbage iført en betaling app.

Menighedens alliance Det forenede kongerige
Jeg kommer med nyheder fra Det Forenede Kongerige og et større Europa! Journalist, redaktør, aktivist, forvaltning af sociale medier, indholdsskaber. Baseret i Det Forenede Kongerige

Relaterede artikler

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *

Tilbage til øverste knap
Tilmeld dig vores nyheder og erindringer nyhedsbreve!

Nyhedsbrev form

Lister
close- link