New “Ghost Tap” Attack Hijacks Android Phones to Drain Bank Accounts
Recent investigations have revealed that Chinese threat actors are exploiting NFC technology to conduct unauthorized financial transactions through Android malware. This activity has resulted in at least $355,000 in fraudulent transactions from a single…
Recent investigations have revealed that Chinese threat actors are exploiting NFC technology to conduct unauthorized financial transactions through Android malware. This activity has resulted in at least $355,000 in fraudulent transactions from a single operation.
Researchers from Group-IB have identified a cybercrime ecosystem utilizing NFC-enabled Android applications for remote tap-to-pay transactions. The malware, known as "Ghost Tap," allows criminals to access bank account funds without needing physical access to payment cards.
The Ghost Tap scheme involves a relay mechanism using two applications: a "reader" on the victim's device and a "tapper" on the attacker's device. Victims are targeted through smishing and vishing campaigns, leading them to install malicious APK files and use their bank cards with their Android devices.
Once the card contacts the compromised phone, the malware captures NFC payment data and transmits it to the attacker's device via command-and-control servers. Attackers then use fraudulently acquired point-of-sale terminals to complete transactions as if the victim's card were present.
In other scenarios, criminals preload mobile wallets with stolen card details and use networks of mules worldwide to make retail purchases using modified tap-to-pay applications.
This activity has resulted in at least $355,000 in fraudulent transactions from a single operation.
Group-IB's analysis identified over 54 APK samples, with some malware variants posing as legitimate banking applications. Researchers noted three major malware vendors on Telegram: TX-NFC, X-NFC, and NFU Pay.
Security researchers found that applications like TX-NFC are obfuscated and packed using 360 Jiagu, a Chinese commercial packer. Data from Group-IB indicates a steady increase in tap-to-pay malware detection from May 2024 to December 2025.
The malware requests critical permissions, such as NFC hardware access and internet connectivity, to maintain persistence. It targets ISO 14443 contactless payment cards and various NFC tag types. Upon detecting an NFC-enabled payment card, it sends the "2PAY.SYS.DDF01" command to initiate communication, storing application identifiers before relaying data through WebSocket services to the attacker's infrastructure.
Code analysis showed that some variants are based on NFCProxy, an open-source project, illustrating how legitimate technologies are repurposed for malicious use.
Oedipus, a Telegram channel associated with TX-NFC vendors, promotes POS terminals from financial institutions in the Middle East, Africa, and Asia. Since November 2024, this operation has processed approximately $355,000 in fraudulent transactions using these stolen terminals.
Authorities worldwide have responded to this threat. Notable arrests include 11 Chinese nationals in Knoxville, Tennessee, in March 2025 for buying gift cards with these applications. Singapore authorities arrested five individuals conducting contactless payments without physical cards in November 2024. Similar arrests have been made by Czech, Malaysian, and Chinese authorities.
The Visa Payment Ecosystem Risk and Control team's Spring 2025 Biannual Threats Report highlighted the ongoing use of NFC-enabled malware for relay fraud. Advisories from Credit China detailed cases where victims lost significant sums to these schemes.
Based on reporting by GBHackers.
