216.73.216.6

New NGate variant hides in a trojanized NFC payment app

· Published 21/04/2026 16:32 · Modified 22/04/2026 08:29

Export JSON

Essential information

Published
21/04/2026 16:32
Modified
22/04/2026 08:29
Tags
2026-04-21 ai-generated code brazil targeting fake lottery handypay trojanization nfc relay ngate payment card fraud phantomcard pin theft
Related entities
6 observables, 1 techniques (mitre), 2 malware, 7 others

Description

ESET researchers have identified a new malware variant targeting Android users in Brazil since November 2025. The threat actors trojanized the legitimate HandyPay NFC payment application, likely using , to relay NFC data from victims' payment cards to attacker-controlled devices. The malware enables unauthorized ATM withdrawals and payments while also capturing and exfiltrating payment card PINs to command-and-control servers. Distribution occurs through two channels: a fake Rio de Prêmios lottery website where victims always win a rigged prize, and a fraudulent Google Play page offering a fake card protection app. Both distribution sites are hosted on the same domain. This campaign represents an evolution in NFC-based fraud, with attackers choosing to patch existing legitimate applications rather than using established malware-as-a-service offerings.

External references