Cybercriminals have devised a new method to cash in on stolen credit card details linked to mobile payment systems like Apple Pay and Google Pay, dubbed “Ghost Tap,” which relays NFC card data to money mules worldwide.
See also: Liminal Panda hackers use GSM, SIGTRAN protocols to attack telecommunications

The tactic builds on methods previously used by mobile malware such as NGate , documented by ESET in August, which involved transmitting Near Field Communication (NFC) signals from payment cards.
Ghost Tap is more obscure and harder to detect, does not require the victim's card or device, does not require ongoing victim exchange, and involves funds in multiple remote locations interacting with Point of Sale (PoS).
Mobile security firm Threat Fabric discovered Ghost Tap and is warning about the growing adoption and potential of the new tactic, saying it has recently noticed a surge in the use of this tactic.
See also: Millions of domains at risk from the “Sitting Ducks” cyberattack
The first step in the attack is the theft of payment card data and interception of one-time passwords (OTPs), which are required for virtual wallet registration on Apple Pay and Google Pay.

Theft of payment card data can be achieved through banking malware that displays overlays that mimic digital payment applications or through phishing and keystroke logging. OTPs can be stolen through social engineering or by malware that monitors text messages.
With the new Ghost Tap feature, threat actors no longer make ATM withdrawals. Instead, they only make withdrawals at points of sale and distribute them to a wide network of mules worldwide.
This blurs the path to the main operators of the malicious activity, only putting the mules at risk.
See also: The Mexican Government was targeted by the Ransomhub gang
NFC payments represent a convenient and secure method for making transactions using smartphones. Near Field Communication (NFC) technology allows two devices to exchange data over short distances, typically between a smartphone and a payment terminal. This technology is commonly used in contactless payment systems and enables users to make purchases with a single tap of their phone. By storing credit or debit card information on the device, NFC mobile payments eliminate the need to carry physical cards, adding an extra layer of security through encryption and token creation.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
