
昂贵的包租每月数百美元. 廉价的那个人藏在一个要求捐赠的付费应用程序里. 后来一个甚至没有等待受害者安装中继器.
ESET researcher Lukáš Štefanko named a malware family NGate because it turns one Android phone into a pipe for someone else’s contactless card. The victim holds a debit or credit card against the back of a handset that does not need to be rooted. The malware captures the NFC exchange and relays it to an attacker’s device, which then emulates the card at a terminal or an NFC-capable ATM. AEGIS联盟 is treating the 2024 Czech cash-outs as the origin story, not the whole market. By the spring and summer of 2026, the same idea had a price list, a Brazilian disguise, a measured surge in blocked attacks, and a cousin kit that a caller could plant during a thirteen-minute phone call.
一个实验室工具,然后是捷克现金
NGate borrowed from NFCGate, an open project that began at TU Darmstadt so researchers could study NFC traffic. Academic code does not stay in the paper. Criminal crews folded the idea into dropper apps and aimed them at bank customers who had already been softened by phishing. The campaign against Czech clients started in November 2023. NGate samples showed up in March 2024. Targets included customers of Raiffeisenbank and ČSOB. Czech police arrested a 22-year-old that March with 160,000 Czech koruna. ESET’s 2024年8月论文 称它为野外观察到的第一台Android恶意软件来完成中继器并转化为现金.
Host Card Emulation is the detail banks still underplay. Modern Android can let an app register as a payment service, read the APDU traffic when a physical card is tapped on the phone, and ship that stream across the internet. The second device can be standing at an ATM in another city. Distance is a network problem, not a radio problem. The plastic never leaves the victim’s wallet. The money does. Callers posed as bank staff and told people a “protective” app would lock the card if they tapped the plastic “to verify.” Contactless ceilings and online-authorization rules vary by issuer, which is why some taps died at the terminal and some did not. The kit did not need every tap. It needed enough of them to pay for itself.
汉地派是因为它便宜才选的
By late 2025, CERT Polska was describing NGate-style relays against Polish customers, with HostApduService used to present stolen card data at ATMs. Parallel kits were sold as malware-as-a-service under names such as NFU Pay, TX-NFC, and PhantomCard. ESET later put numbers on the shopping decision. NFU Pay advertised at almost $400 a month. TX-NFC was around $500. HandyPay, a legitimate NFC-relay app that has been on Google Play since 2021, asked for a €9.99 monthly donation, if it asked for anything. It also needed no exotic permissions beyond being set as the default payment app. That is why the operators patched HandyPay instead of renting a full panel.
On April 21, 2026, ESET published the chapter. The campaign had been running since about November 2025 and was aimed at Android users in Brazil. The trojanized builds shipped off the real Play Store as PROTECAO_CARTAO.apk and Rio_de_Prêmios_Pagamento.apk, pushed through a fake card-protection page and a fake lottery site for Rio de Prêmios, including a WhatsApp “you won” pitch. Both sites sat on the same domain. 我们的安全 said the added code looked machine-written, down to emoji-stuffed log lines. Victims typed a PIN into a text box during a fake scan. That PIN left over plain HTTP to a command server, separate from the NFC path, so the attackers were not limited to a single contactless ceiling. ESET’s telemetry on the command server showed four compromised devices, all in Brazil, with captured PINs, IP addresses, and timestamps. The malicious HandyPay build was never on the official store.
被封锁的攻击数 然后13分钟的电话
Kaspersky’s telemetry, published June 1, 2026, put a scale on the category rather than on one family. From January through April 2026 its products blocked 35,600 Android attacks that used NFC techniques, including SuperCard X, PhantomCard, NGate, and other malicious modifications of NFCGate. That was a 188 percent increase from just over 12,300 blocks in the same four months of 2025. The company said users in Russia hit these lures most often, with Latin America and Europe close behind. Chief security expert Sergey Golovanov drew a line between “direct NFC,” where the victim is talked into tapping a card on an infected phone, and a newer “reverse NFC” pattern in which the victim is steered into sending money themselves. Direct relay is the NGate pattern. It is no longer a Czech footnote.
On August 12, 2026, Group-IB documented a related but distinct family it named WindRelay, deployed beside a SpyNote remote-access trojan. In the investigated case, a caller pretending to be the bank talked a victim through installing a sideloaded app during a call that lasted about thirteen minutes. SpyNote then let the fraudster install WindRelay without a second consent ritual and without turning on screen sharing. The victim was told to tap the physical card and enter a PIN. WindRelay streamed the live NFC exchange to a criminal device at a terminal. The same remote access was used to open a loan inside the victim’s real banking app. Group-IB linked 23 WindRelay samples uploaded to VirusTotal between November 2025 and July 2026, with lures impersonating institutions in Czechia, Slovakia, and Slovenia, plus four command addresses. Malwarebytes later said its Android product detected the pair under NGate-family names, which is a detection label, not proof that the code is Štefanko’s original sample.
银行假设的房间
Tap-to-pay is often safer than a magstripe at a shop counter. The old threat model assumed the card and the reader were in the same room, held by the person who owns the card. NGate and WindRelay break the room. The reader can be a second phone. The card can be in a kitchen in Prague or São Paulo. An RFID sleeve does nothing once the owner is persuaded to tap the plastic on their own handset. Play Protect helps against sloppy sideloads. It does not help a person who installs a “bank” APK from a caller and sets it as the default wallet.
AEGIS联盟已经覆盖了这个问题的硬件表弟 FM11RF08S 旅馆后门. 不同的芯片,相同的课:为方便而建造相近. 相关资金调动文件包括: 暗影黑客银行排水警告,则 700 信用漏洞,则 代理网络Google说它中断了。卡片数据一旦离开塑料,即可重新使用。
There is no vendor patch for a person who installs a fake wallet. Do not sideload payment apps from lottery pages, WhatsApp links, or a caller who will not let you hang up. Do not set an unknown app as the default payment service. Do not type a card PIN into anything except the bank’s own application from the official store. If someone asks you to tap your card on your phone to “unlock” it, hang up and call the number printed on the card, from a different phone if you can. Issuers can lower tap limits, force online authorization, and kill a token after one odd ATM. Those controls are uneven. A customer who has never heard of Host Card Emulation will still tap if the voice sounds like the fraud department.
Defenders who blocked only the 2024 package names will miss PROTECAO_CARTAO, the lottery APK, and whatever label WindRelay wears next month. ESET published hashes for the NGate sets. Group-IB published the thirteen-minute chain. The economics are the part worth remembering: a €9.99 relay app, patched with code that looks machine-written, plus a trojan that installs the next relay for you. See 黑客新闻 和 技术新闻,则 电报创建案例对于另一场争吵 一个工具的设计允许做什么。 这台已经空出现金机器了









