Chinese Hackers Use NFC-Enabled Android Malware to Steal Payment Information
A recent campaign by Chinese threat actors has been identified, involving the distribution of NFC-enabled Android malware. This malware intercepts and remotely relays payment card data via Telegram.
A recent campaign by Chinese threat actors has been identified, involving the distribution of NFC-enabled Android malware. This malware intercepts and remotely relays payment card data via Telegram.
Named "Ghost Tap" and associated with groups such as TX-NFC and NFU Pay, this malware uses social engineering to trick users into installing APKs, leading to unauthorized transactions worldwide.
Security researchers at Group-IB discovered over 54 distinct malware samples, some mimicking legitimate banking and financial apps.
The malware represents an advancement in mobile payment fraud, utilizing Near Field Communication (NFC) relay technology to facilitate global contactless card fraud.
The attack begins with social engineering campaigns that promote seemingly legitimate financial applications through compromised APK repositories. Once installed, the malware creates a relay between the victim's NFC-enabled device and attacker-controlled command-and-control (C2) servers.
This involves a two-device relay setup. The victim's smartphone acts as a reader near payment cards, while an attacker-controlled device communicates with point-of-sale (POS) terminals or ATMs.
By relaying card data through C2 infrastructure, the attackers bypass proximity requirements of legitimate NFC transactions, enabling unauthorized purchases and cash withdrawals globally.
A recent campaign by Chinese threat actors has been identified, involving the distribution of NFC-enabled Android malware.
Group-IB researchers documented that the malware is distributed exclusively via Telegram channels, utilizing subscription-based access models for revenue generation.
TX-NFC, the main vendor, offers subscription plans from $45 for a single day to $1,050 for three months. This indicates a sophisticated criminal service providing NFC relay capabilities to cybercriminals.
The malware variants allow customization, enabling buyers to set attack parameters tailored to specific needs. The group provides 24-hour Telegram-based customer support, showing operations akin to legitimate software vendors.
The code includes encryption, command-and-control obfuscation, and anti-analysis features to evade mobile security detection.
Telemetry data shows the malware targets victims across Europe, Asia, and other regions, with significant activity in Brazil, Italy, Malaysia, Turkey, Uzbekistan, Greece, and Indonesia. These areas have high contactless payment adoption and lower mobile security awareness.
The choice of targets suggests a focus on regions where NFC-based fraud detection is less developed.
This operation highlights the merging of mobile malware capabilities with payment fraud infrastructure. Unlike traditional card skimming, NFC relay technology allows fraudsters to bypass physical security, two-factor authentication, and real-time transaction monitoring.
The organized nature of TX-NFC and NFU Pay operations, evident in their customer support, subscription models, and technical sophistication, indicates a structured cybercriminal enterprise.
Financial institutions and payment processors should prioritize mobile endpoint security, monitor transactions for unusual NFC relay patterns, and conduct public awareness campaigns about installing financial apps from trusted sources.
Based on reporting by GBHackers.
