ESET NGate Malware Relays NFC Card Data to Clone Contactless Payments Then Returns Inside a Fake HandyPay App


The first public write-up treated NGate as a Czech ATM trick. The second wave hid inside a payment app and asked victims to type their PIN.
ESET researcher Lukáš Štefanko named the family NGate because it turns one Android phone into a pipe for someone else’s contactless card. A victim with a non-rooted handset holds a credit or debit card to the back of the phone. The malware relays that NFC traffic to an attacker’s device, which then emulates the card at an NFC-capable ATM or terminal. The AEGIS Alliance is pairing this file with hardware badge research because both attacks live in the two inches between a chip and a reader. The 2024 paper was not the end of the family. In April 2026 the same researchers found a new build inside a trojanized copy of HandyPay, a legitimate NFC-relay app, aimed at Android users in Brazil and built to steal PINs as well as tap data.
How a Research Tool Became a Cash-Out Kit
NGate abused code from NFCGate, an open project that started at TU Darmstadt so academics could study NFC traffic. Research tools do not stay in labs. Criminal crews patched the idea into dropper apps and sent them at bank customers who had already been primed by phishing. The campaign against Czech clients started in November 2023. NGate itself showed up in samples in March 2024. Targets included customers of Raiffeisenbank and ČSOB. Czech police arrested a 22-year-old in March 2024 with 160,000 Czech koruna. ESET’s August 2024 paper called it the first Android malware observed in the wild to complete that relay.
The victim phone does not need to be rooted. That is the detail banks keep underplaying. Host Card Emulation on modern Android is enough for the malware to register as a payment service, capture APDU traffic when a physical card is tapped against the handset, and ship that stream to a second device. The second device can be standing at an ATM a city away. Distance is a network problem, not a radio problem. The card never leaves the victim’s wallet. The money does.
Social engineering did the rest. Callers posed as bank security staff. They told customers a « protective » app would lock the card. They told them to tap the plastic on the phone « to verify. » Once the tap happened, the attacker had a live clone for as long as the session lasted. Contactless limits and offline-tap rules vary by issuer, which is why some cash-outs worked and some died at the terminal. The malware did not need every tap to work. It needed enough taps to pay for the kit.
Poland, Brazil, and a Market for Relay Kits
By late 2025 the technique was no longer a Czech novelty. CERT Polska described NGate-style relays against Polish bank customers, with HostApduService used to present stolen card data at ATMs. Zimperium and other mobile-threat vendors treated the family as a product line, not a one-off sample. Parallel kits sold as malware-as-a-service under names such as NFU Pay, TX-NFC, and PhantomCard. Brazil became a busy market because PIX culture and NFC cash-out both reward speed.
On April 21, 2026, ESET published the HandyPay chapter. Operators took a real app that already knew how to relay NFC, patched it, and shipped the result off Google Play as PROTECAO_CARTAO.apk and Rio_de_Prêmios_Pagamento.apk. WeLiveSecurity said the extra code looked machine-written, complete with the emoji-laden log lines that large language models like to sprinkle into scripts. The campaign had been running since about November 2025. Four compromised devices in ESET’s telemetry sat in Brazil. Distribution sites impersonated card-protection pages and a lottery brand. A WhatsApp « you won » pitch pushed people toward the APK.
The HandyPay fork changed the economics. A monthly « donation » tier on the real app is cheap compared with renting a full malware-as-a-service panel. The patched build needed no exotic permissions beyond being set as the default payment app. Victims typed a PIN into a text box during the fake scan. That PIN left the phone over HTTP to a command server, separate from the NFC relay path. An attacker who has both the tap stream and the PIN is not limited to a single contactless ceiling. That is a different crime than the 2024 ATM trick, even if the family name stayed the same.
Why Contactless Still Looks Safe Until It Does Not
Banks spent a decade telling customers that tap-to-pay was safer than a magstripe. In a store, that is often true. The threat model assumed the card and the terminal were in the same room. NGate breaks the room. The terminal can be an attacker’s phone. The card can be in a kitchen in Prague or São Paulo. RFID-blocking sleeves do nothing once the owner is talked into tapping the card on their own handset. Play Protect helps against sloppy sideloads and does nothing for a user who installs a « bank security » APK and grants it payment defaults.
The AEGIS Alliance has already covered the hardware cousin of this problem in the FM11RF08S hotel-badge backdoor. Different chips, same lesson. Proximity protocols were designed for convenience. They were not designed for a world where one endpoint is malware. Related fraud and account-takeover files include the Phantom Hacker bank-drain warning and the 700Credit breach that exposed millions of car buyers. Card data is reusable. Once it leaves the plastic, the plastic is no longer the perimeter.
Issuers can lower tap limits, require online authorization, and kill a token after a single odd ATM. Those controls are uneven across countries and banks. A customer who has never heard of Host Card Emulation will still tap a card on a phone if a caller sounds like the fraud department. That is why the HandyPay lure worked. It looked like a wallet feature, not a crime tool.
What Readers Can Do Without Waiting for a Patch
There is no vendor patch for a person who installs a fake wallet. Do not sideload payment apps from lottery pages, WhatsApp links, or « card protection » domains. Do not set an unknown app as the default payment service. Do not type a card PIN into any app that is not the official bank application downloaded from the Play Store. If a caller asks you to tap your card on your phone to « unlock » it, hang up and call the number on the back of the card. Google Play Protect should stay on. That is a floor, not a ceiling.
Banks that still treat NFC relays as a European curiosity are late. The 2024 Czech arrests proved the cash-out. The 2026 Brazilian samples proved the product can be restyled, translated, and sold with a PIN stealer attached. ESET published hashes and infrastructure on GitHub under its NGate IOC set. Defenders who only blocked last year’s package names will miss this year’s APK labels.
See The AEGIS Alliance Hacker News and Tech News desks, and the Telegram founder indictment for another case where a tool’s design is being treated as the crime. NGate is not a theoretical demo. It is a relay that already emptied cash machines, then came back wearing a payment app.









