216.73.217.22

NFCShare Android Trojan: NFC card data theft via malicious APK

· Published 30/01/2026 08:18 · Modified 30/01/2026 08:51

Export JSON

Essential information

Published
30/01/2026 08:18
Modified
30/01/2026 08:51
Tags
2026-01-30 android banking card theft data exfiltration nfc nfcshare phishing trojan websocket
Related entities
2 observables, 1 malware, 3 others

Description

A new , named , has been discovered targeting Deutsche Bank customers through a campaign. The malware, disguised as a app update, prompts users to perform a fake card verification process. It exploits technology to steal card data and PINs, which are then exfiltrated to a remote endpoint. The 's distribution, user flow, and technical analysis are detailed, including its reading capabilities and string obfuscation techniques. The malware shows links to Chinese-linked tooling and similarities to other -based threats. IOCs include hashes, package details, and network indicators.

External references