#ngate
#BREAKING #ESETresearch NFC Android malware impersonates banking app in 🇵🇱 Poland. #NGate malware impersonates a banking verification application to steal NFC data and PIN from victims’ physical payment card. x.com/LukasStefanko
🧵1/3
February 8, 2025 at 12:09 PM
Doctor Web says it found new versions of the NGate banking trojan in Russia.

"This trojan relays data from the NFC chip of the compromised device, allowing the attacker to withdraw money from the victim's accounts at ATMs without any victim's involvement."

news.drweb.com/show/?i=1496...
Contactless banking for thee (and for thief): NFC money theft scheme reaches Russian users
Malware analysts at “Doctor Web” warn about the emergence of new versions of the NGate banking trojan, targeting users in Russia. This trojan relays data from the NFC chip of the compromised device, a...
news.drweb.com
January 2, 2025 at 1:48 PM
A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool.
NGate malware variant uses HandyPay NFC app to steal card data
A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool.
www.bleepingcomputer.com
April 21, 2026 at 9:00 AM
#BREAKING #ESETresearch uncovered an active NGate Android malware campaign targeting Spanish speaking users, combining fake app distribution, NFC relay abuse, PIN harvesting, and a shared Devil NFC MaaS backend. The operation is tied to the Devil NFC infrastructure used in Spain since Jan 2026 1/10
April 23, 2026 at 12:21 PM
#ESETresearch discovered a new #NGate malware variant that abuses the legitimate #HandyPay app, which has been patched with possibly AI-generated malicious code. The campaign is ongoing and targets Android users in Brazil. www.welivesecurity.com/en/eset-rese... 1/6
www.welivesecurity.com
April 21, 2026 at 9:03 AM
The threat actor can then use it to withdraw money from ATM via contactless terminal without having payment card.
More information about NGate malware: www.welivesecurity.com/en/eset-rese...
2/3
NGate Android malware relays NFC traffic to steal cash
ESET Research uncovers Android malware that relays NFC data from victims’ payment cards, via victims’ mobile phones, to the device of a perpetrator waiting at an ATM.
www.welivesecurity.com
February 8, 2025 at 12:10 PM
Firmato l'appello, per quanto io trovo che sia venuta l'ora delle spr@ngate.

Per questo non mi ritrovo qui, dove c'è ancora l'illusione che la civiltà e il dialogo possano fare qualcosa.

Questa volta l'Italia non può stare dalla parte sbagliata della Storia, a costo di impiccare maiali per strada.
March 5, 2025 at 3:40 PM
IoCs are available in our GitHub repo: github.com/eset/malware... 6/6
malware-ioc/ngate at master · eset/malware-ioc
Indicators of Compromises (IOC) of our various investigations - eset/malware-ioc
github.com
April 21, 2026 at 9:03 AM
Besonders perfide: sie müssen dafür nicht im Besitz eurer Kredit- oder Debitkarte sein. Die Masche trägt den Namen NGate und nutzt die Near Field Communication (NFC) Funktion aus, die eigentlich für das kontaktlose Bezahlen gedacht ist.
Neue Masche: So wird euer Handy zur Geldquelle für Kriminelle
Was wie eine Sicherheitsprüfung beginnt, entpuppt sich als ein raffinierter Trick. Mit der NGate-Falle heben Betrüger einfach Geld am Automaten von eurem Konto ab.
www.netzwelt.de
December 19, 2025 at 12:06 PM
Falls ihr mit dem Hand zahlt.
Die Malware NGate leitet NFC‑Kartendaten und sogar die PIN über den Handy‑Pay‑Dienst an die Angreifer weiter, sodass sie eure Karte nachbauen und Geld abheben können.
Sofort löschen: Diese App greift den PIN eurer Bankkarte ab
Die Sicherheitsforscher von ESET warnen aktuell vor gefälschten Versionen der Bezahl-App "Handy Pay". In diesen verbirgt sich eine Malware, die sogar den PIN eurer Bankkarte klaut.
www.netzwelt.de
April 26, 2026 at 9:12 AM
New NGate Android malware uses NFC chip to steal credit card data
New NGate Android malware uses NFC chip to steal credit card data
A new Android malware named NGate can steal money from payment cards by relaying to an attacker's device the data read by the near-field communication (NFC) chip.
www.bleepingcomputer.com
August 22, 2024 at 5:17 PM
watching oce*ngate. i have met a few people in leadership positions like rush whose colossal narcissisms and failures will never get the same amount of exposure because they cause less obvious harm. but they do still cause harm.
June 30, 2025 at 1:34 AM
#NGate captures NFC card data and relays it to an attacker-controlled device, which uses the data for ATM withdrawals or POS payments—all without physical access to the victim’s card. We described #NGate in details in our blogpost in 2024
www.welivesecurity.com/en/eset-rese... 3/4
November 6, 2025 at 2:00 PM
-Perforce servers widely exposed on the internet
-The Hormuz scams are here
-Malware reports on The Gentlemen, Kyber, TwizAdmin, NGate, PhantomCLR, Gh0st RAT, Formbook, FudCrypt
-Ukrainian APT goes after TrueConf
-EU sanctions hit the Kremlin disinfo peddler
-Major KEV update
April 22, 2026 at 10:07 AM
NFC Nightmare: New NGate Trojan Drains Bank Accounts via ATMs
https://securityonline.info/nfc-nightmare-new-ngate-trojan-drains-bank-accounts-via-atms/
December 29, 2024 at 10:55 AM
#ESETresearch’s Lukas Stefanko will speak at Ransomware Resilience 2026 on Mon, Jan 19 in Kuala Lumpur at 4pm local time! Discover how Android NFC threats evolved to enable unauthorized ATM withdrawals. Learn about NGate - first Android malware to execute NFC relay attack for remote ATM cash-outs.
January 16, 2026 at 12:37 PM
#ESETresearch identified an active campaign distributing #NGate – Android NFC relay malware used for contactless payment fraud – targeting Brazilian users.
It is available for download via fake Google Play sites mimicking 4 major banks and 1 e-commerce app. 1/4
November 6, 2025 at 2:00 PM
It shares the same package name (com.billy.cardemv) as some #NGate / #PhantomCard variants targeting Brazil, suggesting it could be a new version still focused on Brazil. 2/4
November 6, 2025 at 2:00 PM
IoCs:
IoCs are available in our GitHub repo: github.com/eset/malware... 10/10
malware-ioc/ngate at master · eset/malware-ioc
Indicators of Compromises (IOC) of our various investigations - eset/malware-ioc
github.com
April 23, 2026 at 12:21 PM
--Ukraine sources claim large-scale, multi-year access to Russian army docs,
--New variant of NGate malware hides in HandyPay,
--The Gentlemen claims theft of data from software consultancy The Adaptavist, 4/5
April 21, 2026 at 2:15 PM