Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

NGate Malware Enables Unauthorized Cash Withdrawals at ATMs Using Victims’ Payment Cards

NGate represents a sophisticated Android-based threat that exploits NFC technology to enable unauthorized ATM cash withdrawals without physically stealing payment cards.Rather than stealing cards outright, threat actors use an ingenious relay attack that…

NGate represents a sophisticated Android-based threat that exploits NFC technology to enable unauthorized ATM cash withdrawals without physically stealing payment cards.Rather than stealing cards outright, threat actors use an ingenious relay attack that intercepts the card’s NFC communications from a victim’s Android phone and transmits them to an attacker-controlled device positioned at an ATM, bypassing traditional security measures and enabling fraudulent transactions.The NGate campaign initiates through carefully orchestrated social engineering tactics designed to lower victim vigilance.Targets receive phishing messages via email or SMS claiming to address technical problems or security incidents, with links directing victims to fraudulent pages that encourage installation of what appears to be a legitimate banking application.Samples analyzed show malicious APKs distributed through file-hosting services, creating multiple distribution pathways.The attack intensifies when threat actors pose as bank staff through phone calls, creating a false sense of authority and legitimacy.These scammers claim to “confirm identity” and justify the need for the malicious application. To reinforce credibility, victims simultaneously receive SMS messages appearing to confirm the caller’s identity as an alleged bank employee a coordinated deception that significantly increases the likelihood of successful compromise.Once installed, the application prompts victims to verify their payment card directly within the app interface. This crucial step requires placing the physical card against the phone’s NFC reader and entering the card’s PIN using an on-screen keypad.Multiple samples targeting various banks.This seemingly routine verification process becomes the pivotal moment where compromise occurs, as the malware captures the card’s complete NFC data exchange—the identical information that flows during legitimate ATM transactions.NFC Relay and C2 CommunicationThe NGate malware registers itself as a Host Card Emulation (HCE) payment service on Android, enabling the phone to behave as a virtual payment card.The malware’s server address and operational parameters remain hidden within an encrypted asset bundled with the application, decrypted using a key derived from the APK’s signing certificate SHA-256 hash.Analysis of captured samples revealed a live C2 infrastructure endpoint at IP 91.84.97.13 on port 5653. When victims tap their card, the malware captures all NFC exchanges and transmits them alongside the entered PIN to the attacker’s C2 server or directly to an attacker-controlled device positioned at an ATM.The attacker then replays this card data combined with the PIN to the ATM terminal, bypassing authentication mechanisms and withdrawing cash.The communication protocol uses a simple framed format consisting of frame length (4 bytes), opcode (4 bytes), and message body. Notably, this sample transmitted traffic over plaintext TCP without TLS encryption, making interception straightforward for network analysts tracking the threat.Organizations and individuals should implement immediate mitigation strategies. Download banking applications exclusively from official app stores Google Play Store or Apple App Store—as these platforms maintain security review processes that reduce malicious application distribution.Additionally, never provide personal information over phone calls received unsolicited; instead, hang up and independently call your bank using numbers from official statements or websites. This verification method definitively confirms caller authenticity and prevents social engineering success.Banking institutions should alert customers about NGate through security communications and educate users on this evolving threat landscape.Indicators of CompromiseIndicator TypeValueMD5 Hash2cee3f603679ed7e5f881588b2e78ddcMD5 Hash701e6905e1adf78e6c59ceedd93077f3MD5 Hash2cb20971a972055187a5d4ddb4668cc2MD5 Hashb0a5051df9db33b8a1ffa71742d4cb09MD5 Hashbcafd5c19ffa0e963143d068c8efda92IP Address:Port91.84.97.13:5653URLfiles[.]fm/u/yfwsanu886Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Based on reporting by GBHackers.

Advertisement
AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories