New Android Malware NGate Threatens Contactless Payment Security

26 Aug 2024

In a concerning development for mobile security, cybersecurity researchers have identified a new strain of Android malware, dubbed NGate, which poses a significant threat to contactless payment systems. This sophisticated malware has the capability to intercept and relay payment data from victims' physical credit and debit cards to devices controlled by attackers, facilitating fraudulent transactions.

According to a report from a Slovak cybersecurity firm, the NGate malware has been linked to a targeted campaign against three banks in Czechia. Researchers Lukáš Štefanko and Jakub Osmani noted that this malware operates through a malicious application installed on victims' Android devices, allowing it to transmit sensitive payment information to an attacker’s rooted Android phone.

NGate's Origins and Methodology

The NGate malware is part of a larger scheme that has been active since November 2023, utilizing malicious progressive web apps (PWAs) and WebAPKs to infiltrate financial institutions. The first recorded instance of NGate appeared in March 2024, marking the beginning of a troubling trend in cybercrime.

The primary objective of these attacks is to clone near-field communication (NFC) data from victims' payment cards. Once the data is captured, it is sent to an attacker-controlled device, which can then mimic the original card to withdraw funds from ATMs. Interestingly, NGate is based on a legitimate tool called NFCGate, initially developed for security research by students at TU Darmstadt in 2015.

Social Engineering and Phishing Tactics

The attack methodology appears to involve a combination of social engineering tactics and SMS phishing. Victims are often misled into installing NGate through deceptive links that impersonate legitimate banking websites or mobile banking applications. Between November 2023 and March 2024, researchers identified six different NGate applications, which ceased operations following the arrest of a 22-year-old suspect by Czech authorities for ATM-related theft.

NGate not only exploits the NFCGate functionality to capture NFC traffic but also prompts users to input sensitive financial information, such as their banking client ID, date of birth, and PIN code. This phishing operation is conducted through a WebView interface, where victims are instructed to enable NFC on their smartphones and place their payment cards against the back of their devices for recognition.

Complexity and Deception

Adding to the complexity of the attacks, victims who have installed the malicious PWA or WebAPK are often contacted by individuals posing as bank employees. These impersonators inform victims that their accounts have been compromised due to the installation of the app, further manipulating them into changing their PINs and validating their banking cards through another malicious app, NGate, which is also distributed via SMS links. Notably, there is no evidence that these harmful applications were made available through the Google Play Store.

Researchers have detailed that NGate operates using two distinct servers: one serves as a phishing website designed to extract sensitive information and initiate NFC relay attacks, while the other functions as an NFCGate relay server, redirecting NFC traffic from victims’ devices to the attackers’ systems.

Related Threats

In a related note, Zscaler ThreatLabz has reported on a new variant of the Copybara Android banking trojan, which has been disseminated through voice phishing (vishing) attacks. This variant, active since November 2023, employs the MQTT protocol to communicate with its command-and-control server, leveraging the accessibility service feature inherent to Android devices.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508586
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735529
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746751
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
496422
downloads

News and reviews for Mobile Android

Top Coin Apps Enhance Coin Valuation and Identification

Coin apps improve currency valuation and identification, aiding collectors and investors in the U.S. as of 2026. Key apps include CoinKnow and PCGS CoinFacts.

Read more

Optimize Android Apps Beyond Frontend with Backend Focus

Android apps need robust architecture and backend integration for high performance. Developers should focus beyond the UI to address backend challenges.

Read more

Explore Alternatives as Android Auto Exits Vehicles

Automakers shift from Android Auto, prompting tech users to adapt with alternatives.

Read more

WeChat Faces Potential U.S. Ban Amid Security Concerns

WeChat, a Tencent-owned app, may face a U.S. ban due to alleged ties with Chinese criminal networks, impacting national security.

Read more

Discounted Android App Deals for Gamers and Users

Discover top Android app deals available now, featuring discounted games for 2026-01-27.

Read more

iA Writer Boosts Focus for Writing-First Users

iA Writer helps reclaim focus for writers with distraction-free design. Notion users may prefer its simplicity for dedicated writing tasks.

Read more

Android Deals: Price Drops on Top Apps and Games

Check out the latest Android deals featuring popular games like D&D Lords of Waterdeep and Beastie Bay DX.

Read more

Today's Top App Deals: Lords of Waterdeep & More

Discover the latest app deals on Android with price drops for top games including Lords of Waterdeep and Legends of Heropolis.

Read more

Warframe Expands to Android with Cross Play, Save Features

Warframe launches on Android 2025-02-18, offering Cross Play and Save. Players gain rewards for early participation.

Read more

Waze Enhances Features for Android Auto Users

Waze adds improved navigation and alerts on Android Auto. Users in the US, Canada, Mexico, and France will see changes soon.

Read more