Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New “Ghost Tap” Attack Hijacks Android Phones to Drain Bank Accounts

Recent investigations have revealed that Chinese threat actors are exploiting NFC technology to conduct unauthorized financial transactions through Android malware. This activity has resulted in at least $355,000 in fraudulent transactions from a single…

Recent investigations have revealed that Chinese threat actors are exploiting NFC technology to conduct unauthorized financial transactions through Android malware. This activity has resulted in at least $355,000 in fraudulent transactions from a single operation.

Researchers from Group-IB have identified a cybercrime ecosystem utilizing NFC-enabled Android applications for remote tap-to-pay transactions. The malware, known as "Ghost Tap," allows criminals to access bank account funds without needing physical access to payment cards.

The Ghost Tap scheme involves a relay mechanism using two applications: a "reader" on the victim's device and a "tapper" on the attacker's device. Victims are targeted through smishing and vishing campaigns, leading them to install malicious APK files and use their bank cards with their Android devices.

Once the card contacts the compromised phone, the malware captures NFC payment data and transmits it to the attacker's device via command-and-control servers. Attackers then use fraudulently acquired point-of-sale terminals to complete transactions as if the victim's card were present.

In other scenarios, criminals preload mobile wallets with stolen card details and use networks of mules worldwide to make retail purchases using modified tap-to-pay applications.

This activity has resulted in at least $355,000 in fraudulent transactions from a single operation.
Carter Hartwell · Thehackingpost

Group-IB's analysis identified over 54 APK samples, with some malware variants posing as legitimate banking applications. Researchers noted three major malware vendors on Telegram: TX-NFC, X-NFC, and NFU Pay.

Security researchers found that applications like TX-NFC are obfuscated and packed using 360 Jiagu, a Chinese commercial packer. Data from Group-IB indicates a steady increase in tap-to-pay malware detection from May 2024 to December 2025.

The malware requests critical permissions, such as NFC hardware access and internet connectivity, to maintain persistence. It targets ISO 14443 contactless payment cards and various NFC tag types. Upon detecting an NFC-enabled payment card, it sends the "2PAY.SYS.DDF01" command to initiate communication, storing application identifiers before relaying data through WebSocket services to the attacker's infrastructure.

Code analysis showed that some variants are based on NFCProxy, an open-source project, illustrating how legitimate technologies are repurposed for malicious use.

Advertisement

Oedipus, a Telegram channel associated with TX-NFC vendors, promotes POS terminals from financial institutions in the Middle East, Africa, and Asia. Since November 2024, this operation has processed approximately $355,000 in fraudulent transactions using these stolen terminals.

Authorities worldwide have responded to this threat. Notable arrests include 11 Chinese nationals in Knoxville, Tennessee, in March 2025 for buying gift cards with these applications. Singapore authorities arrested five individuals conducting contactless payments without physical cards in November 2024. Similar arrests have been made by Czech, Malaysian, and Chinese authorities.

The Visa Payment Ecosystem Risk and Control team's Spring 2025 Biannual Threats Report highlighted the ongoing use of NFC-enabled malware for relay fraud. Advisories from Credit China detailed cases where victims lost significant sums to these schemes.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories