Malware · 146 days ago
A legitimate payments app can become a card-stealing layer on top of normal NFC use. The standard response is to think about stolen card numbers, but this variant turns the phone itself into the collection point, so the attacker can build virtual cards without ever touching the physical card.
ESET says the new NGate variant hides inside a trojanized HandyPay app and abuses NFC-based data transmission on Android devices. The campaign has been active since November 2025 and is targeting Android users in Brazil; the malware captures payment card data through the device’s NFC chip and sends it to the attacker for fraudulent purchases or ATM withdrawals.
The shift from noisier, expensive NFC relaying tools to a cheap, legitimate-looking app lowers the barrier to this kind of fraud. That makes routine mobile payment use a direct source of payment data, and the risk persists even when the card itself never leaves the victim’s possession.
5 sources covering this story
NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs
NGate abuses HandyPay in Brazil since Nov 2025, stealing NFC data and PINs to enable ATM fraud and unauthorized payments.
Trojanized Android App Fuels New Wave of NFC Fraud
NGate malware abuses HandyPay app to steal NFC card data and PINs in Brazil
NGate NFC malware targets Android users through trojanized payment app - Help Net Security
NGate NFC malware is targeting Android users via a trojanized payment app, stealing card PINs and relaying NFC data to attacker devices.
New NGate variant hides in a trojanized NFC payment app
ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI.
NGate Android malware uses HandyPay NFC app to steal card data
A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool.
Part of the PlainSec briefing for 2026-04-22