{"id":1041606,"date":"2024-08-25T23:24:25","date_gmt":"2024-08-26T06:24:25","guid":{"rendered":"https:\/\/theaegisalliance.com\/?p=1041606"},"modified":"2026-10-05T09:56:19","modified_gmt":"2026-10-05T16:56:19","slug":"ngate-android-malware-steals-nfc-data-clones-no-contact-payment-cards","status":"publish","type":"post","link":"https:\/\/theaegisalliance.com\/fr\/2024\/08\/25\/ngate-android-malware-steals-nfc-data-clones-no-contact-payment-cards\/","title":{"rendered":"NGate&rsquo;s HandyPay Clone and a 13-Minute WindRelay Call Show How NFC Relays Empty Contactless Cards"},"content":{"rendered":"<div class=\"epyt-video-wrapper\">\n<div  style=\"display: block; margin: 0px auto;\"  id=\"_ytid_95770\"  width=\"480\" height=\"270\"  data-origwidth=\"480\" data-origheight=\"270\" data-facadesrc=\"https:\/\/www.youtube.com\/embed\/q69--5rdlmI?enablejsapi=1&#038;origin=https:\/\/theaegisalliance.com&#038;autoplay=0&#038;cc_load_policy=0&#038;iv_load_policy=1&#038;loop=0&#038;fs=1&#038;playsinline=0&#038;controls=1&#038;disablekb=0&#038;color=red&#038;cc_lang_pref=&#038;rel=0&#038;autohide=2&#038;theme=dark&#038;\" class=\"__youtube_prefs__ epyt-facade epyt-is-override  no-lazyload\" data-epautoplay=\"1\" ><img decoding=\"async\" data-spai-excluded=\"true\" class=\"epyt-facade-poster skip-lazy\" loading=\"lazy\"  alt=\"Unmasking NGate | ESET Research\"  src=\"https:\/\/i.ytimg.com\/vi\/q69--5rdlmI\/maxresdefault.jpg\"  \/><button class=\"epyt-facade-play\" aria-label=\"Play\"><svg data-no-lazy=\"1\" height=\"100%\" version=\"1.1\" viewBox=\"0 0 68 48\" width=\"100%\"><path class=\"ytp-large-play-button-bg\" d=\"M66.52,7.74c-0.78-2.93-2.49-5.41-5.42-6.19C55.79,.13,34,0,34,0S12.21,.13,6.9,1.55 C3.97,2.33,2.27,4.81,1.48,7.74C0.06,13.05,0,24,0,24s0.06,10.95,1.48,16.26c0.78,2.93,2.49,5.41,5.42,6.19 C12.21,47.87,34,48,34,48s21.79-0.13,27.1-1.55c2.93-0.78,4.64-3.26,5.42-6.19C67.94,34.95,68,24,68,24S67.94,13.05,66.52,7.74z\" fill=\"#f00\"><\/path><path d=\"M 45,24 27,14 27,34\" fill=\"#fff\"><\/path><\/svg><\/button><\/div>\n<\/div>\n<p><em><strong>The expensive kits rent for hundreds of dollars a month. The cheap one hid inside a payment app that asked for a donation. A later one did not even wait for the victim to install the relay.<\/strong><\/em><\/p>\n<p>ESET researcher Luk\u00e1\u0161 \u0160tefanko named a malware family NGate because it turns one Android phone into a pipe for someone else&rsquo;s contactless card. The victim holds a debit or credit card against the back of a handset that does not need to be rooted. The malware captures the NFC exchange and relays it to an attacker&rsquo;s device, which then emulates the card at a terminal or an NFC-capable ATM. <a href=\"https:\/\/theaegisalliance.com\/\">The AEGIS Alliance<\/a> is treating the 2024 Czech cash-outs as the origin story, not the whole market. By the spring and summer of 2026, the same idea had a price list, a Brazilian disguise, a measured surge in blocked attacks, and a cousin kit that a caller could plant during a thirteen-minute phone call.<\/p>\n<h2>A lab tool, then a Czech cash-out<\/h2>\n<p>NGate borrowed from NFCGate, an open project that began at TU Darmstadt so researchers could study NFC traffic. Academic code does not stay in the paper. Criminal crews folded the idea into dropper apps and aimed them at bank customers who had already been softened by phishing. The campaign against Czech clients started in November 2023. NGate samples showed up in March 2024. Targets included customers of Raiffeisenbank and \u010cSOB. Czech police arrested a 22-year-old that March with 160,000 Czech koruna. ESET&rsquo;s <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/ngate-android-malware-relays-nfc-traffic-to-steal-cash\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">August 2024 paper<\/a> called it the first Android malware observed in the wild to finish that relay and turn it into cash.<\/p>\n<p>Host Card Emulation is the detail banks still underplay. Modern Android can let an app register as a payment service, read the APDU traffic when a physical card is tapped on the phone, and ship that stream across the internet. The second device can be standing at an ATM in another city. Distance is a network problem, not a radio problem. The plastic never leaves the victim&rsquo;s wallet. The money does. Callers posed as bank staff and told people a \u00ab\u00a0protective\u00a0\u00bb app would lock the card if they tapped the plastic \u00ab\u00a0to verify.\u00a0\u00bb Contactless ceilings and online-authorization rules vary by issuer, which is why some taps died at the terminal and some did not. The kit did not need every tap. It needed enough of them to pay for itself.<\/p>\n<div class=\"embed-x\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"cs\" dir=\"ltr\">Podvodn\u00edk zavol\u00e1 jako \u201ebanka\u201c, p\u0159im\u011bje v\u00e1s nainstalovat aplikaci a nakonec chce, abyste p\u0159ilo\u017eili platebn\u00ed kartu k vlastn\u00edmu telefonu.<\/p>\n<p>WindRelay pak p\u0159es NFC p\u0159en\u00e1\u0161\u00ed komunikaci karty v re\u00e1ln\u00e9m \u010dase k \u00fato\u010dn\u00edkovi. A n\u011bkter\u00e9 vzorky u\u017e napodobuj\u00ed \u010desk\u00e9 banky. <a href=\"https:\/\/t.co\/PlI8nlBjZ8\">pic.twitter.com\/PlI8nlBjZ8<\/a><\/p>\n<p>&mdash; Sv\u011bt Androida cz (@SvetAndroida) <a href=\"https:\/\/x.com\/SvetAndroida\/status\/2089636672912629936?ref_src=twsrc%5Etfw\">August 18, 2026<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.x.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<h2>HandyPay was chosen because it was cheap<\/h2>\n<p>By late 2025, CERT Polska was describing NGate-style relays against Polish customers, with HostApduService used to present stolen card data at ATMs. Parallel kits were sold as malware-as-a-service under names such as NFU Pay, TX-NFC, and PhantomCard. ESET later put numbers on the shopping decision. NFU Pay advertised at almost $400 a month. TX-NFC was around $500. HandyPay, a legitimate NFC-relay app that has been on Google Play since 2021, asked for a \u20ac9.99 monthly donation, if it asked for anything. It also needed no exotic permissions beyond being set as the default payment app. That is why the operators patched HandyPay instead of renting a full panel.<\/p>\n<p>On April 21, 2026, ESET published the chapter. The campaign had been running since about November 2025 and was aimed at Android users in Brazil. The trojanized builds shipped off the real Play Store as PROTECAO_CARTAO.apk and Rio_de_Pr\u00eamios_Pagamento.apk, pushed through a fake card-protection page and a fake lottery site for Rio de Pr\u00eamios, including a WhatsApp \u00ab\u00a0you won\u00a0\u00bb pitch. Both sites sat on the same domain. <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">WeLiveSecurity<\/a> said the added code looked machine-written, down to emoji-stuffed log lines. Victims typed a PIN into a text box during a fake scan. That PIN left over plain HTTP to a command server, separate from the NFC path, so the attackers were not limited to a single contactless ceiling. ESET&rsquo;s telemetry on the command server showed four compromised devices, all in Brazil, with captured PINs, IP addresses, and timestamps. The malicious HandyPay build was never on the official store.<\/p>\n<h2>The blocked-attack count, then a thirteen-minute call<\/h2>\n<p>Kaspersky&rsquo;s telemetry, published June 1, 2026, put a scale on the category rather than on one family. From January through April 2026 its products blocked 35,600 Android attacks that used NFC techniques, including SuperCard X, PhantomCard, NGate, and other malicious modifications of NFCGate. That was a 188 percent increase from just over 12,300 blocks in the same four months of 2025. The company said users in Russia hit these lures most often, with Latin America and Europe close behind. Chief security expert Sergey Golovanov drew a line between \u00ab\u00a0direct NFC,\u00a0\u00bb where the victim is talked into tapping a card on an infected phone, and a newer \u00ab\u00a0reverse NFC\u00a0\u00bb pattern in which the victim is steered into sending money themselves. Direct relay is the NGate pattern. It is no longer a Czech footnote.<\/p>\n<p>On August 12, 2026, Group-IB documented a related but distinct family it named WindRelay, deployed beside a SpyNote remote-access trojan. In the investigated case, a caller pretending to be the bank talked a victim through installing a sideloaded app during a call that lasted about thirteen minutes. SpyNote then let the fraudster install WindRelay without a second consent ritual and without turning on screen sharing. The victim was told to tap the physical card and enter a PIN. WindRelay streamed the live NFC exchange to a criminal device at a terminal. The same remote access was used to open a loan inside the victim&rsquo;s real banking app. Group-IB linked 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026, with lures impersonating institutions in Czechia, Slovakia, and Slovenia, plus four command addresses. Malwarebytes later said its Android product detected the pair under NGate-family names, which is a detection label, not proof that the code is \u0160tefanko&rsquo;s original sample.<\/p>\n<div class=\"embed-x\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/x.com\/hashtag\/WindRelay?src=hash&amp;ref_src=twsrc%5Etfw\">#WindRelay<\/a> <a href=\"https:\/\/x.com\/hashtag\/Android?src=hash&amp;ref_src=twsrc%5Etfw\">#Android<\/a> <a href=\"https:\/\/x.com\/hashtag\/Malware?src=hash&amp;ref_src=twsrc%5Etfw\">#Malware<\/a> Turns Victims&#39; <a href=\"https:\/\/x.com\/hashtag\/Phones?src=hash&amp;ref_src=twsrc%5Etfw\">#Phones<\/a> Into <a href=\"https:\/\/x.com\/hashtag\/NFC?src=hash&amp;ref_src=twsrc%5Etfw\">#NFC<\/a> <a href=\"https:\/\/x.com\/hashtag\/Relays?src=hash&amp;ref_src=twsrc%5Etfw\">#Relays<\/a> for <a href=\"https:\/\/x.com\/hashtag\/Payment_Fraud?src=hash&amp;ref_src=twsrc%5Etfw\">#Payment_Fraud<\/a> <a href=\"https:\/\/t.co\/uXDqFa7qJ1\">https:\/\/t.co\/uXDqFa7qJ1<\/a> <a href=\"https:\/\/t.co\/PzRBZKZJHA\">pic.twitter.com\/PzRBZKZJHA<\/a><\/p>\n<p>&mdash; omvapt (@omvapt) <a href=\"https:\/\/x.com\/omvapt\/status\/2089692801596293195?ref_src=twsrc%5Etfw\">August 18, 2026<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.x.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<h2>The room the banks assumed<\/h2>\n<p>Tap-to-pay is often safer than a magstripe at a shop counter. The old threat model assumed the card and the reader were in the same room, held by the person who owns the card. NGate and WindRelay break the room. The reader can be a second phone. The card can be in a kitchen in Prague or S\u00e3o Paulo. An RFID sleeve does nothing once the owner is persuaded to tap the plastic on their own handset. Play Protect helps against sloppy sideloads. It does not help a person who installs a \u00ab\u00a0bank\u00a0\u00bb APK from a caller and sets it as the default wallet.<\/p>\n<p>The AEGIS Alliance has already covered the hardware cousin of this problem in the <a href=\"https:\/\/theaegisalliance.com\/2024\/08\/22\/hardware-backdoor-found-in-rfid-cards-used-in-offices-and-hotels-all-over-the-world\/\">FM11RF08S hotel-badge backdoor<\/a>. Different chips, same lesson: proximity was built for convenience. Related money-movement files include the <a href=\"https:\/\/theaegisalliance.com\/2025\/10\/31\/fbi-warns-of-new-phantom-hacker-scam-draining-bank-accounts-a-closer-look\/\">Phantom Hacker bank-drain warning<\/a>, the <a href=\"https:\/\/theaegisalliance.com\/2025\/12\/17\/inside-the-700credit-breach-that-exposed-nearly-6-million-car-buyers\/\">700Credit breach<\/a>, and the <a href=\"https:\/\/theaegisalliance.com\/2026\/01\/31\/google-dismantles-a-shadow-network-that-secretly-used-your-phones-internet\/\">proxy network Google said it had disrupted<\/a>. Card data is reusable once it leaves the plastic.<\/p>\n<p>There is no vendor patch for a person who installs a fake wallet. Do not sideload payment apps from lottery pages, WhatsApp links, or a caller who will not let you hang up. Do not set an unknown app as the default payment service. Do not type a card PIN into anything except the bank&rsquo;s own application from the official store. If someone asks you to tap your card on your phone to \u00ab\u00a0unlock\u00a0\u00bb it, hang up and call the number printed on the card, from a different phone if you can. Issuers can lower tap limits, force online authorization, and kill a token after one odd ATM. Those controls are uneven. A customer who has never heard of Host Card Emulation will still tap if the voice sounds like the fraud department.<\/p>\n<p>Defenders who blocked only the 2024 package names will miss PROTECAO_CARTAO, the lottery APK, and whatever label WindRelay wears next month. ESET published hashes for the NGate sets. Group-IB published the thirteen-minute chain. The economics are the part worth remembering: a \u20ac9.99 relay app, patched with code that looks machine-written, plus a trojan that installs the next relay for you. See <a href=\"https:\/\/theaegisalliance.com\/category\/news\/hacker-news\/\">Hacker News<\/a> and <a href=\"https:\/\/theaegisalliance.com\/category\/news\/technology\/\">Tech News<\/a>, and the <a href=\"https:\/\/theaegisalliance.com\/2024\/08\/25\/french-authorities-arrest-telegram-ceo-pavel-durov-at-a-paris-airport\/\">Telegram founder case<\/a>, for another fight over what a tool&rsquo;s design is allowed to do. This one already emptied cash machines.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>NGate relayed contactless cards through Android phones in Czechia, then hid inside a trojanized HandyPay app in Brazil. Group-IB later documented WindRelay, planted during a 13-minute bank-scam call.<\/p>\n","protected":false},"author":299,"featured_media":1041626,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22,23,21],"tags":[217781,206778,191867,214309,192394,213948,214263,192022,3674,206782,52,214307,192240,214308,212875],"class_list":["post-1041606","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacker-news","category-international-news","category-news","tag-android","tag-cyber-news","tag-cybersecurity","tag-czech","tag-data-breach","tag-europe","tag-global-news","tag-hacker-news","tag-hackers","tag-hacking-news","tag-news","tag-nfc","tag-smartphones","tag-social-engineer","tag-world-news"],"jetpack_featured_media_url":"https:\/\/theaegisalliance.com\/wp-content\/uploads\/NGate-Android-Malware-Steals-NFC-Data-Clones-No-Contact-Payment-Cards.jpg","_links":{"self":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/1041606","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/users\/299"}],"replies":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/comments?post=1041606"}],"version-history":[{"count":5,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/1041606\/revisions"}],"predecessor-version":[{"id":1203412,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/posts\/1041606\/revisions\/1203412"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/media\/1041626"}],"wp:attachment":[{"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/media?parent=1041606"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/categories?post=1041606"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/theaegisalliance.com\/fr\/wp-json\/wp\/v2\/tags?post=1041606"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}