Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Chinese Hackers Use NFC-Enabled Android Malware to Steal Payment Information

A recent campaign by Chinese threat actors has been identified, involving the distribution of NFC-enabled Android malware. This malware intercepts and remotely relays payment card data via Telegram.

A recent campaign by Chinese threat actors has been identified, involving the distribution of NFC-enabled Android malware. This malware intercepts and remotely relays payment card data via Telegram.

Named "Ghost Tap" and associated with groups such as TX-NFC and NFU Pay, this malware uses social engineering to trick users into installing APKs, leading to unauthorized transactions worldwide.

Security researchers at Group-IB discovered over 54 distinct malware samples, some mimicking legitimate banking and financial apps.

The malware represents an advancement in mobile payment fraud, utilizing Near Field Communication (NFC) relay technology to facilitate global contactless card fraud.

The attack begins with social engineering campaigns that promote seemingly legitimate financial applications through compromised APK repositories. Once installed, the malware creates a relay between the victim's NFC-enabled device and attacker-controlled command-and-control (C2) servers.

This involves a two-device relay setup. The victim's smartphone acts as a reader near payment cards, while an attacker-controlled device communicates with point-of-sale (POS) terminals or ATMs.

By relaying card data through C2 infrastructure, the attackers bypass proximity requirements of legitimate NFC transactions, enabling unauthorized purchases and cash withdrawals globally.

A recent campaign by Chinese threat actors has been identified, involving the distribution of NFC-enabled Android malware.
Benjamin Scott · Thehackingpost

Group-IB researchers documented that the malware is distributed exclusively via Telegram channels, utilizing subscription-based access models for revenue generation.

TX-NFC, the main vendor, offers subscription plans from $45 for a single day to $1,050 for three months. This indicates a sophisticated criminal service providing NFC relay capabilities to cybercriminals.

The malware variants allow customization, enabling buyers to set attack parameters tailored to specific needs. The group provides 24-hour Telegram-based customer support, showing operations akin to legitimate software vendors.

The code includes encryption, command-and-control obfuscation, and anti-analysis features to evade mobile security detection.

Telemetry data shows the malware targets victims across Europe, Asia, and other regions, with significant activity in Brazil, Italy, Malaysia, Turkey, Uzbekistan, Greece, and Indonesia. These areas have high contactless payment adoption and lower mobile security awareness.

Advertisement

The choice of targets suggests a focus on regions where NFC-based fraud detection is less developed.

This operation highlights the merging of mobile malware capabilities with payment fraud infrastructure. Unlike traditional card skimming, NFC relay technology allows fraudsters to bypass physical security, two-factor authentication, and real-time transaction monitoring.

The organized nature of TX-NFC and NFU Pay operations, evident in their customer support, subscription models, and technical sophistication, indicates a structured cybercriminal enterprise.

Financial institutions and payment processors should prioritize mobile endpoint security, monitor transactions for unusual NFC relay patterns, and conduct public awareness campaigns about installing financial apps from trusted sources.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories