Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

700+ Malicious Android Apps Abusing NFC Relay to Exfiltrate Banking Login Credentials

A sophisticated malware campaign exploiting Near Field Communication technology on Android devices has expanded dramatically since its emergence in April 2024.

A sophisticated malware campaign exploiting Near Field Communication technology on Android devices has expanded dramatically since its emergence in April 2024.

What began as isolated incidents has escalated into a widespread threat, with over 760 malicious applications now circulating in the wild.

These malicious apps abuse NFC and Host Card Emulation capabilities to illegally capture payment data and facilitate fraudulent transactions.

The campaign has broadened its geographical footprint beyond initial targets, now affecting users across Russia, Poland, Czech Republic, Slovakia, and Brazil.

The malware operates by masquerading as legitimate financial institution applications, tricking users into installing apps that appear to represent trusted banks and government agencies.

Once installed, these applications prompt victims to designate them as the default NFC payment method on their devices.

What began as isolated incidents has escalated into a widespread threat, with over 760 malicious applications now circulating in the wild.
Grace Bennett · Thehackingpost

The then silently intercepts payment card data during tap-to-pay transactions, exfiltrating sensitive information including card numbers, expiration dates, and EMV fields to threat actors through private Telegram channels.

Zimperium analysts identified a sprawling infrastructure supporting these operations, uncovering over 70 command-and-control servers, dozens of Telegram bots used for coordination, and approximately 20 impersonated institutions.

Among the targeted entities are major Russian banks like VTB, Tinkoff, and Promsvyazbank, alongside international institutions such as Santander, Bradesco, PKO Bank Polski, and government portals including Russia’s Gosuslugi service.

The malware’s operational methods vary, with some variants functioning as scanner tools that extract card data for subsequent POS purchases, while others directly exfiltrate stolen credentials to attacker-controlled channels.

Communication Architecture and Command Structure

The malicious applications establish persistent connections with command-and-control servers through WebSocket communications, enabling real-time bidirectional exchanges.

Advertisement

The apps execute commands such as register_device, which transmits hardware identifiers, device models, NFC support status, and IP addresses to the server.

The app layout presented by variants of NFC malwares (Source – Zimperium) The apdu_command instruction forwards payment terminal requests to the C2 infrastructure, while apdu_response returns crafted replies that manipulate transaction flows.

Additional commands like card_info and get_pin facilitate the extraction of complete payment credentials, with threat actors receiving automated notifications containing full card details through Telegram integrations via the telegram_notification command.

Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories