Trojanized Payment App Turns Android Phones Into Card Skimmers
A legitimate payments app can become a card-stealing layer on top of normal NFC use. The standard response is to think about stolen card numbers, but this variant turns the phone itself into the collection point, so the attacker can build virtual cards without ever touching the physical card.
ESET says the new NGate variant hides inside a trojanized HandyPay app and abuses NFC-based data transmission on Android devices. The campaign has been active since November 2025 and is targeting Android users in Brazil; the malware captures payment card data through the device’s NFC chip and sends it to the attacker for fraudulent purchases or ATM withdrawals.
The shift from noisier, expensive NFC relaying tools to a cheap, legitimate-looking app lowers the barrier to this kind of fraud. That makes routine mobile payment use a direct source of payment data, and the risk persists even when the card itself never leaves the victim’s possession.