Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    CVE-2026-41039 | THREATINT

    April 21, 2026

    New cross domain guidance for government, industry and the wider security community

    April 21, 2026

    ​​Supply Chain Compromise Impacts Axios Node Package Manager​

    April 21, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»NGate Android malware uses HandyPay NFC app to steal card data
    News

    NGate Android malware uses HandyPay NFC app to steal card data

    adminBy adminApril 21, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    NGate Android malware uses HandyPay NFC app to steal card data

    A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool.

    NGate was originally documented in mid-2024 and steals payment card information through the mobile device’s near-field communication (NFC) chip.

    The data is sent to the attacker, who create virtual cards used for unauthorized purchases or withdrawing cash from ATMs with NFC support. 

    image

    In the earlier versions, the malware used an open-source tool called NFCGate to capture, relay, and replay the payment card information.

    New research from ESET details a new variant that uses a version of the HandyPay app, which has been injected with malicious code to facilitate data-stealing operations.

    The researchers found that code in the new NGate malware contains emojis, which may indicate the use of a generative AI tool for development.

    Malicious code snippet
    Malicious code snippet
    Source: ESET

    HandyPay has been available on Google Play since 2021 and supports NFC-based data transmissions between devices, a feature that NGate abuses to exfiltrate the card information.

    ESET believes the reason behind moving from NFCGate to HandyPay is likely financial, but evasion also plays a key role. The researchers underline the high cost of NFC relaying tools such as NFU Pay and TX-NFC, and the fact that these are “noisy” on infected devices.

    “NFU Pay advertises its product for almost US$400 per month, while TX-NFC goes for around US$500 per month. HandyPay, on the other hand, is significantly cheaper, only asking for the €9.99 per month donation, if even that,” ESET explains.

    “In addition to the price, HandyPay natively does not require any permissions, only to be made the default payment app, helping the threat actors avoid raising suspicion.”

    In terms of targeting, ESET reports that the campaign using this latest variant has been active since November 2025, targeting primarily Android devices in Brazil.

    The campaign relies on two distribution methods. One lures users into downloading a fake app called “Proteção Cartão” that promises card protection features and is hosted on a fake Google Play page.

    The second uses a fake lottery website where visitors “win a prize” and are redirected to WhatsApp to claim it, which eventually leads to downloading the malicious APK.

    Malware distribution methods
    Malware distribution methods
    Source: ESET

    After installation, the app prompts users to set it as the default NFC payment app, requests their card PIN, and asks them to tap their card on the phone for reading.

    All the information collected this way is delivered to an attacker’s email address that is hardcoded into the app.

    Data theft flow
    Data theft flow
    Source: ESET

    Android users are advised to never download APKs from outside Google Play unless they explicitly trust the publisher, disable NFC if not needed, and scan for threats with Play Protect, which detects and blocks the latest NGate malware variant.


    article image

    AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

    At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

    Claim Your Spot



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCVE-2026-6712 | THREATINT
    Next Article Missing Authentication for critical function in CAPWAP daemon
    admin
    • Website

    Related Posts

    News

    New cross domain guidance for government, industry and the wider security community

    April 21, 2026
    News

    China’s Apple App Store infiltrated by crypto-stealing wallet apps

    April 21, 2026
    News

    Why Journalists Are Going Indie (with Maddy Myers)

    April 20, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202623 Views

    The Grandparent Scam: How AI Voice Technology Makes This Old Con Deadlier Than Ever

    March 18, 202620 Views

    Global Takedown of Massive IoT Botnets Halts Record-Breaking Cyberattacks

    March 20, 202619 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202623 Views

    The Grandparent Scam: How AI Voice Technology Makes This Old Con Deadlier Than Ever

    March 18, 202620 Views

    Global Takedown of Massive IoT Botnets Halts Record-Breaking Cyberattacks

    March 20, 202619 Views
    Our Picks

    CVE-2026-41039 | THREATINT

    April 21, 2026

    New cross domain guidance for government, industry and the wider security community

    April 21, 2026

    ​​Supply Chain Compromise Impacts Axios Node Package Manager​

    April 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.