A new Android malware, dubbed NGate, sends card details and NFC data to cybercriminals for ATM withdrawals.

According to security researchers at ESET, the NGate distribution campaign has been active since March 2024 and has targeted customers at at least three Czech banks. Victims unknowingly download the NGate malware onto their Android device through a multi-stage phishing attack.
After it is installed and opened on the device, NGate displays a fake website that asks for the victim’s banking details. These are sent to the attacker’s server.
See also: Singapore: Two men charged with distributing Android malware
However, the most interesting feature, called “NFCGate“, relays near field communication (NFC) data between the victim’s and the attacker’s devices. NFC is a short-range wireless technology used for contactless payments in stores, as well as for ATM withdrawals, along with the user’s PIN.
The NGate malware prompts victims to enter information such as their banking customer ID, date of birth, and their card PIN. It also asks them to enable NFC on their smartphones and place payment next to the device. This allows the malicious application to recognize the card.
With the stolen NFC data and PIN, the attacker can withdraw cash at an ATM. If this technique doesn't work, the attacker still has the victim's banking information and can thus access their account and transfer money.
See also: Android malware PixPirate uses new hiding tactic
How does Android Malware NGate?
The attack has several stages:
- The attacker sends the victim a link phishing via SMS.
- The victim unwittingly installs a malicious app that looks like a legitimate banking app.
- The application asks the user to enter banking information.
- The application sends the credentials to the attacker's server.
- The attacker calls the victim impersonating a bank employee, and mentions a supposed security. He urges them to change their PIN and verify their card via the malicious app.
- The attacker sends an SMS link to download the malware NGate.
- The NGate malware relays the victim's PIN and NFC traffic from their payment card.
See also: XLoader Android malware: New version runs automatically on device

To protect against Android malware, it is important for users to follow some security best practices, such as:
- download apps from trusted sources like the Google Play Store
- Device and app updates
- Be very careful with suspicious links or attachments sent via email or messaging apps.
- In this case, it is also necessary to disable NFC when not necessary.
Additionally, using a reputable antivirus can help detect and remove malware on Android devices. As technology evolves, so do the tactics cybercriminals use to target Android users. Staying informed about potential threats and taking the necessary precautions can help keep your device and personal information safe. Therefore, you should always be vigilant and take preventive measures to protect your Android device from malware!
Source: www.infosecurity-magazine.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
