A new and particularly worrying campaign is highlighting the growing threats surrounding contactless payments. According to security researchers, Chinese threat actors are behind a sophisticated Android malware distribution campaign called Ghost Tap. This malware leverages NFC functionality to steal sensitive financial data from unsuspecting victims worldwide.

A sneaky distribution model through messaging apps
Unlike more “noisy” attacks of the past, Ghost Tap spreads through a carefully designed social engineering model. Attackers lure users into downloading seemingly harmless applications, which are mainly distributed via Telegram and other messaging platforms. The files are presented as popular applications, productivity tools, or even games, reducing suspicion and increasing installation rates.
See also: Microsoft: Incorrect email routing enables internal domain phishing
The choice of such channels is not accidental: outside of official app stores, security checks are limited, giving perpetrators greater freedom of movement.
How Ghost Tap takes advantage of NFC technology
Once installed on the device, Ghost Tap requests access to the Near Field Communication (NFC). Many users, unaware of the implications, approve the request. From that moment on, the malware gains the ability to read payment data when a card is touched to the phone.
The dangerous element is that the process is done silently. The victim receives no notification, while the card data is transmitted to remote servers controlled by the attackers. In effect, the smartphone turns into a “digital skimmer”, capable of collecting financial information without any visible signs of a breach.
What the Group-IB research revealed
The campaign was uncovered by researchers at Group-IB Threat Intelligence, who identified more than 54 unique samples of Ghost Tap across different distribution channels. Their analysis showed that many variants of the malware mimic applications from well-known companies, making it extremely difficult for the average user to distinguish between legitimate and malicious software.
According to the findings, the stolen data is being used for unauthorized transactions through rogue point-of-sale (POS) terminals. Incidents have been recorded in multiple countries, with victims reporting significant financial losses before they even realize their device has been compromised.

Persistence mechanism: The most dangerous feature
One of the most worrying aspects of Ghost Tap is its persistence mechanism. The malware is not limited to running as a simple app, but registers as a system service and ties deeply into NFC framework Android's. This means it can continue to function even if the user deletes the original decoy app.
See also: Chrome extensions have stolen conversations from ChatGPT and DeepSeek
In many cases, malicious functionality reinstalls itself automatically, leveraging compromised operating system processes. Complete removal becomes extremely difficult and often requires specialized security tools or a device reset.
How users and organizations can protect themselves
Experts recommend increased caution when installing applications, especially when they come from unofficial sources. Downloading software only from official app stores and checking the publisher are key protection steps.
Additionally, disabling NFC when not in use significantly reduces the risk of eavesdropping. Users should also be particularly cautious about granting permissions, especially to apps that have no obvious reason to require access to payment functions.

For businesses and organizations, implementing Mobile Device Management (MDM) can prevent the installation of suspicious apps and provide better visibility into potential threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Kimwolf botnet abuses home proxy networks
A warning about the future of contactless payments
The Ghost Tap case highlights a broader trend: as contactless payments become more widespread, so does the interest of cybercriminals. Mobile device security is no longer just a privacy issue, but a critical factor in financial protection in an increasingly digital everyday life.
