NGate malware steals bank data via NFC
Security firm ESET recently reported a piece of malware targeted mainly at Android users, which uses a social engineering attack alongside stolen NFC traffic, to steal bank data from users. Dubbed Ngate, the malware allows attackers to siphon money from affected users' bank accounts. The attack is unique in that it has multiple moving parts, and is reportedly the first seen in the wild to integrate NFC interception as part of a multi-faceted approach.
The way the attack works is relatively simple. It all starts with convincing a user to install a fake version of their banking app of choice. This is accomplished through malicious advertising or progressive web apps that mimic the official interfaces of Google Play and select banking apps to trick users into installing what they're led to believe is something else, usually a critical security update. This is a two-part process; part one is aimed at getting users to grant access to their hardware and bank data, and part two installs the actual malware.
The malware is based on an open-source toolset called NFCGate, which was developed by German college students with the goal of being able to analyze or alter NFC traffic on host devices. NGate, on the other hand, is an app that's made purely to listen and transmit. When the infected device is brought near an NFC-enabled bank card, or any other NFC-enabled tag or card for that matter, the information being broadcast via NFC is captured by the device and relayed to the attackers. From there, they can use an Android device with root privileges enabled to clone that NFC output. This allows them to fool an ATM, or other NFC receptacle, into thinking that they're holding that card or tag. Along with the bank info stolen in the first step, this allows them to access or change a victim's PIN, and withdraw money.
This attack has been found to be active in Czechia since at least November of 2023. This tactic appears to have been used on a limited scale, targeting customers of three Czech banks through six fake apps. One of the people using the malware to steal money was arrested in Prague back in March of 2024, with the rough equivalent of $6,500 in stolen funds on him. His identity and nationality have yet to be revealed. The report noted that use of this attack seems to have stopped since the arrest.
While ESET believes that activity has stopped, it wouldn't be too difficult for another attacker to pick up the same toolset and approach, then give it a facelift for a new audience. It is worth noting that no software containing this particular malware can be found in the official Google Play Store. Google confirmed this to news outlet Bleeping Computer, stating that Google Play Protect contains protections against NGate.
The above is the detailed content of NGate malware steals bank data via NFC. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

Hot Topics











Huawei is rolling out software version 5.0.0.100(C00M01) for the Watch GT 5 and the Watch GT 5 Prosmartwatchesglobally. These two smartwatches recently launched in Europe, with the standard model arriving as the company’s cheapest model. This Harmony

Katsuhiro Harada, the Tekken series director, once seriously tried to bring Colonel Sanders into the iconic fighting game. In an interview with TheGamer, Harada revealed that he pitched the idea to KFC Japan, hoping to add the fast-food legend as a g

Tesla is rolling out the latest Full Self-Driving (Supervised) version 12.5.5 and with it comes the promised Cybertruck FSD option at long last, ten months after the pickup went on sale with the feature included in the Foundation Series trim price. F

Garmin is ending the month with a new set of stable updates for its latest high-end smartwatches. To recap, the company released System Software 11.64 to combat high battery drain across the Enduro 3, Fenix E and Fenix 8 (curr. $1,099.99 on Amazon).

Xiaomi will shortly launch the Mijia Graphene Oil Heater in China. The company recently ran a successful crowdfunding campaign for the smart home product, hosted on its Youpin platform. According to the page, the device has already started to ship to

Earlier in September 2024, Anker's Zolo 140W charger was leaked, and it was a big deal since it was the first-ever wall charger with a display from the company. Now, a new unboxing video from Xiao Li TV on YouTube gives us a first-hand look at the hi

The launch of Samsung's long-awaited 'Special Edition' foldable has taken another twist. In recent weeks, rumours about the so-called Galaxy Z Fold Special Edition went rather quiet. Instead, the focus has shifted to the Galaxy S25 series, including

With a history of over one decade, Manjaro is regarded as one of the most user-friendly Linux distros suitable for both beginners and power users, being easy to install and use. Mostly developed in Austria, Germany, and France, this Arch-based distro
