Malware Enables Criminals to Illegally Obtain Near Field Communication Data

New research conducted by cybersecurity company ESET has uncovered a new cyberattack campaign targeting Android users. The attack utilizes a complex social engineering scheme and new Android malware to steal users’ near field communication data, allowing the cybercriminals to withdraw cash from NFC-enabled ATMs.

Initially, the threat actor used progressive web app technology to trick users into installing malicious apps from websites outside of the Play Store. These apps, accessed through supported browsers, could lead users to phishing websites to collect sensitive information. The threat actor then switched to using WebAPKs, a more advanced form of PWA, to create standalone apps that appear legitimate but are actually malicious.

The attack also involves the distribution of a new malware called NGate, which tricks users into providing banking information through a fake website. The malware also embedded a tool called NFCGate, allowing the cybercriminals to relay NFC data between devices. The stolen information can be used for traditional fraud or to withdraw money from NFC-enabled ATMs.

The campaign has been identified in the Czech Republic, where a suspect has been arrested. However, there is a possibility of the attack spreading to other regions. To protect against this threat, users are advised to verify the source of applications, avoid downloading software from unofficial sources, and avoid sharing payment card PIN codes. Additionally, users should deactivate NFC when not in use and use virtual cards stored securely on devices. Security software should also be installed on mobile devices to detect malware.

Unlock your business potential with our expert guidance. Get in touch now!

Robot-bot-chatbot-AI.jpg

A Jobseeker’s Handbook: Leveraging AI and Its Implications for Employers

tr_20241220-top-software-development-technologies.jpg

8 Key Software Development Technologies to Watch in 2025

cloud-money-finance-investment-savings-adobe.jpg

AWS Provides Hackney Council with a Minimum 22% Discount on Cloud Services via OGVA 2.0

tr_20241219-eu-guidance-ai-privacy-laws.jpg

EU Provides Guidance for AI Developers on Compliance with Privacy Regulations

IT-sustainability-think-tank-hero.jpg

IT Sustainability Think Tank: Insights from 2024 and Key Priorities for 2025

AdobeStock_210063189.jpg

NVIDIA Unveils New Mini Developer Kit for Generative AI

technology-digital-ai-binary-adobe.jpeg

Digital Ethics Summit 2024: Understanding the Socio-Technical Aspects of AI