Chinese Hackers Deploy NFC-enabled Android Malware to Steal Payment Data
Chinese threat actors have initiated a campaign deploying NFC-enabled Android malware, known as Ghost Tap, to intercept and steal financial information from global victims.
Chinese threat actors have initiated a campaign deploying NFC-enabled Android malware, known as Ghost Tap, to intercept and steal financial information from global victims.
The malware is distributed through deceptive methods, enticing users to download seemingly legitimate applications via platforms like Telegram. Upon installation, Ghost Tap utilizes Near Field Communication (NFC) technology to read payment card data when users inadvertently tap their cards against infected devices, capturing sensitive information without user awareness.
The attack strategy heavily employs social engineering techniques to increase infection rates by presenting convincing lures disguised as popular applications, gaming software, or utility tools. Once installed, the malware requests access to NFC functionality, which users often grant without understanding the security implications.
The malware is distributed through deceptive methods, enticing users to download seemingly legitimate applications via platforms like Telegram.
Ghost Tap operates in the background, continuously monitoring NFC card interactions and transmitting stolen data through remote servers controlled by the attackers. Group-IB Threat Intelligence researchers identified the campaign, tracking over 54 unique Ghost Tap samples across various distribution channels. Many variants impersonate legitimate applications, increasing detection difficulty for users. Analysis indicates that stolen payment data is used for unauthorized transactions through illicit point-of-sale terminals, with financial losses reported across multiple countries.
Technical Specifications and Recommendations
The malware's persistence mechanism is a significant technical concern. Ghost Tap employs advanced evasion techniques to maintain its presence on devices, even after attempts to uninstall the applications. It registers as a system service and integrates deeply with Android's NFC framework, allowing independent operation from the parent application. When deletion is attempted, Ghost Tap reinstalls itself by exploiting compromised system processes, making removal challenging without technical expertise or specialized security tools .
Security experts advise exercising caution when installing applications from untrusted sources and verifying app authenticity through official stores. Disabling NFC when not in use adds an extra layer of protection. Organizations are encouraged to implement mobile device management solutions to monitor and block suspicious applications, while users should remain vigilant about granting permissions to software.
Based on reporting by Cyber Security News.
