#HandyPay
A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool.
NGate malware variant uses HandyPay NFC app to steal card data
A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool.
www.bleepingcomputer.com
April 21, 2026 at 9:00 AM
🚀Master Your Money in Minutes with HandyPay Haiti!* 🚀**

**💸 *Your All-in-One Financial Superpower!*

👉Download NOW:

Aso:

(play.google.com/store/apps/d...)

🌐visit:

(handypayhaiti.com)
March 12, 2025 at 8:45 AM
#ESETresearch discovered a new #NGate malware variant that abuses the legitimate #HandyPay app, which has been patched with possibly AI-generated malicious code. The campaign is ongoing and targets Android users in Brazil. www.welivesecurity.com/en/eset-rese... 1/6
www.welivesecurity.com
April 21, 2026 at 9:03 AM
The code inside the maliciously patched HandyPay appears to have been developed with the assistance of #AI, as the logs contain emoji that are typical of AI-generated text, although definitive proof remains elusive. 5/6
April 21, 2026 at 9:03 AM
--Ukraine sources claim large-scale, multi-year access to Russian army docs,
--New variant of NGate malware hides in HandyPay,
--The Gentlemen claims theft of data from software consultancy The Adaptavist, 4/5
April 21, 2026 at 2:15 PM
HandyPay is an Android app that enables relaying #NFC data from one device to another. Using the trojanized version, attackers can transfer victim’s payment card data to their own device and use it for unauthorized payments. The code can also capture payment card PINs. 2/6
April 21, 2026 at 9:03 AM
We found two NGate samples being used in the campaign: one distributed via a website impersonating a 🇧🇷 lottery, the other via a fake Google Play page for a supposed card protection app. The trojanized HandyPay has never been available on the official Google Play store. 4/6
April 21, 2026 at 9:03 AM
NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
April 21, 2026 at 4:10 PM
Since HandyPay is significantly cheaper compared to paying for established #MaaS offerings with similar NFC relay functionality, the threat actors most probably decided on trojanizing the app as a cost-cutting measure. 3/6
April 21, 2026 at 9:03 AM
トロイの木馬化されたAndroidアプリがNFC詐欺の新たな波を引き起こす

Trojanized Android App Fuels New Wave of NFC Fraud #InfosecurityMagazine (Apr 22)

www.infosecurity-magazine.com/news/trojani...
Trojanized Android App Fuels New Wave of NFC Fraud
NGate malware abuses HandyPay app to steal NFC card data and PINs in Brazil
www.infosecurity-magazine.com
April 23, 2026 at 10:01 PM
ESET Research: New NGate hides in NFC payment app and possibly built with AI

ESET Research has discovered a new variant of the NGate malware family that abuses a legitimate Android application called HandyPay, instead of the previously leveraged NFCGate tool. The threat actors took the app, which…
ESET Research: New NGate hides in NFC payment app and possibly built with AI
ESET Research has discovered a new variant of the NGate malware family that abuses a legitimate Android application called HandyPay, instead of the previously leveraged NFCGate tool. The threat actors took the app, which is used to relay NFC data, and patched it with malicious code that appears to have been AI generated. As with previous iterations of NGate, the malicious code allows the attackers to transfer NFC data from the victim's payment card to their own device and use them for contactless ATM cash-outs and unauthorized payments.
itnerd.blog
April 23, 2026 at 2:04 PM
NGate no Brasil: malware imita app HandyPay para clonar cartões via NFC
Pesquisadores da ESET identificaram uma nova variante do malware NGate direcionada a usuários Android no Brasil. Os criminosos modificaram o HandyPay, aplicativo legítimo de NFC, para capturar PINs e dados de cartões de pagamento das vítimas. A campanha usa dois vetores no mesmo domínio: uma página falsa que imita a loteria da Loterj, onde a vítima sempre "ganha" R$ 20 mil e é redirecionada ao WhatsApp com imagem da Caixa Econômica Federal; e uma falsa Google Play Store com app de "proteção de cartão" que instala o APK malicioso. Após a instalação, o app pede para ser o meio de pagamento padrão do celular. Ao digitar o PIN e aproximar o cartão com NFC ativado, os dados são enviados para os criminosos, que realizam saques em caixas eletrônicos por aproximação e pagamentos não autorizados.
www.tecmundo.com.br
April 21, 2026 at 11:21 AM
Read more:
www.technadu.com/new-ngate-ma...

What do you think - are mobile payment systems becoming the next major attack surface? Share your thoughts below.
#Cybersecurity #MobileSecurity #Android #Malware #DataSecurity #Infosec
New NGate Malware Variant Discovered in Trojanized NFC App Stealing Payment Card PINs
New NGate malware variant leverages HandyPay abuse within a trojanized NFC app to steal payment data.
www.technadu.com
April 23, 2026 at 8:48 AM
NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs

thehackernews.com/2026/04/ngat...
NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs
NGate abuses HandyPay in Brazil since Nov 2025, stealing NFC data and PINs to enable ATM fraud and unauthorized payments.
thehackernews.com
April 21, 2026 at 11:34 AM
Malware de Android usa página falsa de loteria para roubar cartões de pagamento
Uma nova variante do malware NGate está sendo usada em ataques direcionados a usuários Android no Brasil. Agora, a ameaça se passa pelo aplicativo HandyPay, um utilitário legítimo de compartilhamento de dados via NFC. O objetivo dos criminosos é capturar dados de cartões de pagamento para realizar saques e transações não autorizadas. A descoberta é da empresa de cibersegurança ESET. O NGate foi identificado pela primeira vez pelos pesquisadores da ESET em 2024, mas eles acreditam que o grupo está ativo na República Tcheca desde novembro de 2023. Em março de 2024, o grupo aprimorou suas táticas com a implantação do malware NGate para Android. E em novembro do mesmo ano, o grupo iniciou seus avanços na América Latina. O código malicioso injetado no HandyPay parece ter sido desenvolvido com ajuda de Inteligência Artificial generativa. Isso porque os pesquisadores encontraram nos logs do malware emojis, uma linguagem típica dos textos gerados por IA. Ao raspar os símbolos, o resultado é sempre um prêmio de R$ 20.000 (esquerda), e a vítima é convidada a abrir o WhatsApp por meio de um botão com os dizeres: 'Resgatar meu prêmio agora' (tradução automática) para reivindicar a recompensa (direita). Imagem: ESET. “Observamos sinais de que ferramentas de inteligência artificial podem ter sido utilizadas no desenvolvimento desse malware, o que reforça um movimento importante: a redução da barreira técnica para a criação de ameaças mais sofisticadas”, afirma Lukáš Štefanko, pesquisador da ESET responsável pela descoberta. ## Como funciona o ataque? A distribuição do malware no Brasil acontece por dois vetores hospedados no mesmo domínio. O primeiro é uma página falsa que imita a loteria gerida pela organização de loteria do Estado do Rio de Janeiro (Loterj). O site mostra um jogo de raspadinha, no qual a vítima sempre sorteia R$ 20 mil. Para resgatar o valor, a vítima é direcionada para o WhatsApp com uma mensagem pré-preenchida para um perfil que usa a imagem da Caixa Econômica Federal. Mensagem pré-preenchida enviada automaticamente ao WhatsApp após a vítima "ganhar" R$ 20 mil na raspadinha falsa da Loterj — o contato usa a imagem da Caixa Econômica Federal para parecer legítimo. Imagem: ESET. O segundo vetor usa uma página falsa da Google Play Store, chamada “Proteção Cartão”, que mostra um suposto aplicativo que protege cartões da vítima. O usuário é instruído a instalar o aplicativo manualmente, usando o arquivo APK, que infecta o dispositivo da vítima com o HandyPay falso. ## O que o NGate pode fazer? Depois da instalação, o app pede para ser definido como o meio de pagamento padrão do celular, uma funcionalidade legítima do HandyPay que não levanta suspeitas. Depois disso, a vítima precisa digitar o PIN do cartão e aproximá-lo do celular com o NFC ativado. É aqui que o golpe começa. Isso porque, nesse processo, o PIN é capturado por um campo de texto malicioso e enviado via HTTP para o servidor de comando e controle dos criminosos. O malware se aproveita da funcionalidade NFC do celular para capturar os dados do cartão no momento em que a vítima o aproxima do dispositivo. Enquanto os criminosos capturam o PIN, os dados do cartão obtidos via NFC são enviados para os dispositivos dos criminosos por meio da própria estrutura do HandyPay. Até mesmo o e-mail do cibercriminoso fica embutido no código do aplicativo, de forma a garantir que todo o tráfego de informações seja direcionado a ele. “Com esses dados em mãos, os criminosos conseguem realizar saques em caixas eletrônicos com tecnologia por aproximação ou efetuar pagamentos não autorizados”, explica Štefanko. ## Uso de IA torna o malware mais barato do que MaaS Um aspecto que chama atenção nesta campanha é o possível uso de IA generativa para criar o código malicioso. Os criminosos optaram por modificar um aplicativo legítimo em vez de utilizar ferramentas já disponíveis no mercado ilegal, como, por exmplo, o “malware como serviço” (MaaS). O NGate está ativo desde novembro de 2023 na República Tcheca e chegou ao Brasil no fim de 2024, segundo a ESET. Segundo a ESET, essa escolha pode estar relacionada ao custo, já que soluções prontas de malware como serviço podem chegar a centenas de dólares por mês, enquanto o aplicativo utilizado tem custo significativamente inferior. “Esse tipo de estratégia mostra que os atacantes estão buscando alternativas mais acessíveis e discretas para conduzir suas operações, reduzindo custos e evitando levantar suspeitas durante o ataque”, acrescenta Štefanko. A ESET também destacou que a versão maliciosa do aplicativo nunca esteve disponível na loja oficial Google Play e que as descobertas foram compartilhadas com o Google e com os desenvolvedores do app legítimo. Acompanhe o TecMundo nas redes sociais. Para mais notícias de segurança e tecnologia, inscreva-se em nossa newsletter e canal do YouTube.
www.tecmundo.com.br
April 21, 2026 at 11:56 AM
ESET uncovers a new NGate variant trojanizing the Android HandyPay app to steal NFC payment data and PINs for contactless ATM cash-outs in Brazil. Malware spread via fake lottery and Google Play sites. #NGate #HandyPay #Brazil
New NGate variant hides in a trojanized NFC payment app
ESET Research discovered a new NGate variant that trojanizes the legitimate Android HandyPay app to relay NFC payment-card data and capture PINs for contactless ATM cash-outs and unauthorized payments. The campaign, active since November 2025 and targeting Android users in Brazil, spread trojanized samples via a fake Rio de Prêmios lottery site and a fake Google Play page, and evidence in the malware logs suggests the malicious code may have been generated with GenAI #NGate #HandyPay
www.hendryadrian.com
April 22, 2026 at 3:00 PM
New NGate Malware Developed Using AI Hides in NFC Payment Apps
New NGate Malware Developed Using AI Hides in NFC Payment Apps
A new and more dangerous version of the NGate malware has been found hiding inside a trojanized NFC payment application. This time, threat actors appear to have used artificial intelligence to help write the malicious code, which marks a significant shift in how cybercriminals are building attack tools today. The malware targets Android users by disguising itself as a legitimate app called HandyPay. HandyPay is a real Android application available on Google Play since 2021, designed to relay NFC data between two devices for everyday uses like card sharing. Attackers took this app, quietly patched it with harmful code, and began distributing it outside the official Google Play Store. Once installed on a victim’s phone, the trojanized version silently reads payment card data via NFC and forwards it to an attacker-controlled device. The attacker can then use that stolen card data to make contactless ATM withdrawals and unauthorized payments. In addition to stealing NFC data, the malware can also capture the victim’s payment card PIN and send it to the attackers’ command-and-control (C2) server over HTTP. WeLiveSecurity analysts and researchers identified this new NGate variant and noted that the malicious code showed clear signs of AI generation, including emojis left in log entries that are typical of text produced by large language models. The campaign has been running since November 2025 and continues to actively target Android users in Brazil. The attacks are carried out through two separate distribution channels. The first uses a fake lottery website that impersonates a Brazilian state lottery organization called Rio de Premios. The site shows a rigged scratch card game where the user always wins R$20,000 and is then directed to send a WhatsApp message to claim the prize, after which they are guided to download the trojanized app. The second channel is a fake Google Play page distributing the malware under the name Protecao Cartao, meaning Card Protection in English. Geographical distribution of NGate attacks from January 2025 to February 2026 (Source – Welivesecurity) Both websites were hosted on the same domain, strongly indicating a single threat actor behind the entire operation. How the Trojanized App Works Once a user installs the fake HandyPay app, the infection process begins with a simple but effective setup. The app asks to be set as the default NFC payment application on the device. This request does not look suspicious because it is part of the original HandyPay functionality. The app also asks the victim to enter their payment card PIN and then tap their physical card to the back of their phone. At that point, the malware reads the NFC card data and forwards it through the HandyPay relay service to the attacker’s device, which is linked to a hardcoded email address inside the malicious app. Trojanized HandyPay operational flow (Source – Welivesecurity) What makes this variant especially dangerous is that no special permissions are needed on the victim’s device to relay NFC data. The malicious app only requires being set as the default payment app, keeping the attack well below the radar of standard permission-based security checks . Example of PIN exfiltration to the C2 server over HTTP (Source – Welivesecurity) The card PIN is exfiltrated separately to the C2 server, giving attackers everything needed to perform both contactless payments and ATM cash-outs. Users should only download payment apps directly from official sources like the Google Play Store and avoid installing apps from third-party websites or links shared over messaging apps. Enabling Google Play Protect on Android devices provides added protection, as it automatically detects known versions of this malware. Users should never enter their payment card PIN into a newly installed or unfamiliar app, especially one claiming to be a prize or card protection tool . If a payment app requests NFC access without coming from a trusted source, uninstall it immediately and report the incident to the relevant bank or card issuer. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post New NGate Malware Developed Using AI Hides in NFC Payment Apps appeared first on Cyber Security News .
cybersecuritynews.com
April 21, 2026 at 3:54 PM
NGate Android malware uses HandyPay NFC app to steal card data
NGate Android malware uses HandyPay NFC app to steal card data
A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool.
www.bleepingcomputer.com
April 21, 2026 at 9:33 AM