HomeSecurityGhost Tap: New Android malware steals payment data

Ghost Tap: New Android malware steals payment data

A new and particularly worrying campaign is highlighting the growing threats surrounding contactless payments. According to security researchers, Chinese threat actors are behind a sophisticated Android malware distribution campaign called Ghost Tap. This malware leverages NFC functionality to steal sensitive financial data from unsuspecting victims worldwide.

Ghost Tap Android malware

A sneaky distribution model through messaging apps

Unlike more “noisy” attacks of the past, Ghost Tap spreads through a carefully designed social engineering model. Attackers lure users into downloading seemingly harmless applications, which are mainly distributed via Telegram and other messaging platforms. The files are presented as popular applications, productivity tools, or even games, reducing suspicion and increasing installation rates.

See also: Microsoft: Incorrect email routing enables internal domain phishing

The choice of such channels is not accidental: outside of official app stores, security checks are limited, giving perpetrators greater freedom of movement.

How Ghost Tap takes advantage of NFC technology

Once installed on the device, Ghost Tap requests access to the Near Field Communication (NFC). Many users, unaware of the implications, approve the request. From that moment on, the malware gains the ability to read payment data when a card is touched to the phone.

The dangerous element is that the process is done silently. The victim receives no notification, while the card data is transmitted to remote servers controlled by the attackers. In effect, the smartphone turns into a “digital skimmer”, capable of collecting financial information without any visible signs of a breach.

What the Group-IB research revealed

The campaign was uncovered by researchers at Group-IB Threat Intelligence, who identified more than 54 unique samples of Ghost Tap across different distribution channels. Their analysis showed that many variants of the malware mimic applications from well-known companies, making it extremely difficult for the average user to distinguish between legitimate and malicious software.

According to the findings, the stolen data is being used for unauthorized transactions through rogue point-of-sale (POS) terminals. Incidents have been recorded in multiple countries, with victims reporting significant financial losses before they even realize their device has been compromised.

Android adware

Persistence mechanism: The most dangerous feature

One of the most worrying aspects of Ghost Tap is its persistence mechanism. The malware is not limited to running as a simple app, but registers as a system service and ties deeply into NFC framework Android's. This means it can continue to function even if the user deletes the original decoy app.

See also: Chrome extensions have stolen conversations from ChatGPT and DeepSeek

In many cases, malicious functionality reinstalls itself automatically, leveraging compromised operating system processes. Complete removal becomes extremely difficult and often requires specialized security tools or a device reset.

How users and organizations can protect themselves

Experts recommend increased caution when installing applications, especially when they come from unofficial sources. Downloading software only from official app stores and checking the publisher are key protection steps.

Additionally, disabling NFC when not in use significantly reduces the risk of eavesdropping. Users should also be particularly cautious about granting permissions, especially to apps that have no obvious reason to require access to payment functions.

Ghost Tap: New Android malware steals payment data

For businesses and organizations, implementing Mobile Device Management (MDM) can prevent the installation of suspicious apps and provide better visibility into potential threats.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Kimwolf botnet abuses home proxy networks

A warning about the future of contactless payments

The Ghost Tap case highlights a broader trend: as contactless payments become more widespread, so does the interest of cybercriminals. Mobile device security is no longer just a privacy issue, but a critical factor in financial protection in an increasingly digital everyday life.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS