κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / New Android Malware Wave Hits Banking via NFC Relay Fraud, Call Hijacking, and Root Exploits
άμυνα
.

New Android Malware Wave Hits Banking via NFC Relay Fraud, Call Hijacking, and Root Exploits

14/08/2025

Cybersecurity researchers have disclosed a new Android trojan called PhantomCard that abuses near-field communication (NFC) to conduct relay attacks for facilitating fraudulent transactions in attacks targeting banking customers in Brazil.
“PhantomCard relays NFC data from a victim’s banking card to the fraudster’s device,” ThreatFabric said in a report. “PhantomCard is based on Chinese-originating NFC relay malware-as-a-service.”
The Android malware, distributed via fake Google Play web pages mimicking apps for card protection, goes by the name “Proteção Cartões” (package name “com.nfupay.s145” or “com.rc888.baxi.English”).
The bogus pages also feature deceptive positive reviews to persuade victims into installing the app. It’s currently not known how links to these pages are distributed, but it likely involves smishing or a similar social engineering technique.
Once the app is installed and opened, it requests victims to place their credit/debit card on the back of the phone to begin the verification process, at which point the user interface displays the message: “Card Detected! Keep the card nearby until authentication is complete.”
In reality, the card data is relayed to an attacker-controlled NFC relay server by taking advantage of the built-in NFC reader built into modern devices. The PhantomCard-laced app then requests the victim to enter the PIN code with the goal of transmitting the information to the cybercriminal so as to authenticate the transaction.
“As a result, PhantomCard establishes a channel between the victim’s physical card and the PoS terminal / ATM that the cybercriminal is next to,” ThreatFabric explained. “It allows the cybercriminal to use the victim’s card as if it was in their hands.”

Similar to SuperCard X, there exists an equivalent app on the mule-side that’s installed on their device to receive the stolen card information and ensure seamless communications between the PoS terminal and the victim’s card.

The Dutch security company said the actor behind the malware, Go1ano developer, is a “serial” reseller of Android threats in Brazil, and that PhantomCard is actually the handiwork of a Chinese malware-as-a-service offering known as NFU Pay that’s advertised on Telegram.
Go1ano developer, in their own Telegram channel, claims PhantomCard works globally, stating it is 100% undetectable and is compatible with all NFC-enabled point-of-sale (PoS) terminal devices. They also claim to be a “trusted partner” for other malware families like BTMOB and GhostSpy in the country.

It’s worth noting that NFU Pay is one of the many illicit services peddled on the underground that offer similar NFC relay capabilities, such as SuperCard X, KingNFC, and X/Z/TX-NFC.
“Such threat actors pose additional risks to local financial organizations as they open the doors for a wider variety of threats from all over the world, which could have potentially stayed away from certain regions due to language and cultural barriers, specifics of financial system, lack of cash-out ways,” ThreatFabric said.
“This, consequently, complicates the threat landscape for local financial organizations and calls out for proper monitoring of the global threats and actors behind it targeting the organization.”
In a report published last month warning of a spike in NFC-enabled fraud in the Philippines, Resecurity said Southeast Asia has become a testing ground for NFC fraud, with bad actors targeting regional banks and financial service providers.
“With tools such as Z-NFC, X-NFC, SuperCard X, and Track2NFC, attackers can clone stolen card data and perform unauthorized transactions using NFC-enabled devices,” Resecurity said.

“These tools are widely available in underground forums and private messaging groups. The resulting fraud is difficult to detect, as the transactions appear to originate from trusted, authenticated devices. In markets like the Philippines, where contactless payment usage is rising and low-value transactions often bypass PIN verification, such attacks are harder to trace and stop in real time.”
The disclosure comes as K7 Security uncovered an Android malware campaign dubbed SpyBanker aimed at Indian banking users that’s likely distributed to users via WhatsApp under the guise of a customer help service app.
“Interestingly, this Android SpyBanker malware edits the ‘Call Forward Number’ to a hard-coded mobile number, controlled by the attacker, by registering a service called ‘CallForwardingService’ and redirects the user’s calls,” the company said. “Incoming calls to the victims when left unattended are diverted to the call forwarded number to carry out any desired malicious activity.”
Furthermore, the malware comes fitted with capabilities to collect victims’ SIM details, sensitive banking information, SMS messages, and notification data.

Indian banking users have also been targeted by Android malware that’s designed to siphon financial information, while simultaneously dropping the XMRig cryptocurrency miner on compromised devices. The malicious credit card apps are distributed via convincing phishing pages that use real assets taken from official banking websites.
The list of malicious apps is as follows –

  • Axis Bank Credit Card (com.NWilfxj.FxKDr)
  • ICICI Bank Credit Card (com.NWilfxj.FxKDr)
  • IndusInd Credit Card (com.NWilfxj.FxKDr)
  • State Bank of India Credit Card (com.NWilfxj.FxKDr)

The malware is designed to display a bogus user interface that prompts victims to enter their personal information, including names, card numbers, CVV codes, expiry dates, and mobile numbers. A notable aspect of the app is its ability to listen to specific messages sent via Firebase Cloud Messaging (FCM) to trigger the mining process.

“The app delivered through these phishing sites functions as a dropper, meaning it initially appears harmless but later dynamically loads and executes the actual malicious payload,” McAfee researcher Dexter Shin said. “This technique helps evade static detection and complicates analysis.”
“These phishing pages load images, JavaScript, and other web resources directly from the official websites to appear legitimate. However, they include additional elements such as ‘Get App’ or ‘Download’ buttons, which prompt users to install the malicious APK file.”

The findings also follow a report from Zimperium zLabs detailing how rooting frameworks like KernelSU, APatch, and SKRoot can be used to gain root access and escalate privileges, allowing an attacker to gain full control of Android devices.
The mobile security company said it discovered in mid-2023 a security flaw in KernelSU (version 0.5.7) that it said could allow attackers to authenticate as the KernelSU manager and completely compromise a rooted Android device via a malicious application already installed on it that also bundles the official KernelSU manager APK.
However, an important caveat to pull off this attack is that it’s only effective if the threat actor application is executed before the legitimate KernelSU manager application.
“Because system calls can be triggered by any app on the device, strong authentication and access controls are essential,” security researcher Marcel Bathke said. “Unfortunately, this layer is often poorly implemented – or entirely neglected – which opens the door to serious security risks. Improper authentication can allow malicious apps to gain root access and fully compromise the device.”
Source: thehackernews.com

Filed Under: INDUSTRY NEWS Tagged With: Source-2

NotebookLM’s new Learning Guide feeature completely changed the way I study with the tool

Given how much I love NotebookLM and how often I use the tool, if it got no new features beyond its iconic Audio Overviews and Mind Maps, I’d likely not complain. At the same time, new features are always exciting, especially when they genuinely change the way you use a tool. Source: xda-developers.com … [Read More...]

Google’s latest Lab experiment is NotebookLM but better

I’ve tried every NotebookLM competitor I’ve come across, but none have managed to match its capabilities. The only tool that seemed to help me more than NotebookLM when I was studying was a Google Labs experiment called Learn About. Source: xda-developers.com … [Read More...]

The Roku Streaming Stick Plus drops to a new record-low price for Prime Day

If you're looking for a way to upgrade an old TV or add a more convenient smart interface to your main set, Roku devices are good ways to do that. Thanks to Prime Day deals that you can already get now, you can get one of our favorite Roku streaming devices for less than $30. The Roku Streaming Stick Plus is on sale for just $24 right now, which is 40 percent off and the lowest price we've seen.We … [Read More...]

Apple's AirPods 4 drop to $90 for Prime Day

If you prefer open-ear AirPods but still have an older model, this deal could be worth noting. Amazon's October Prime Day has the AirPods 4 on sale for $90, or 30 percent off their usual price. That's also the lowest we've seen them.When Apple updated its standard AirPods in 2024, it released two models: one with active noise cancellation (ANC) and one without. We consider the non-ANC models to be … [Read More...]

I ditched dynamic DNS for a new-fangled alternative

While Dynamic DNS addresses solve one problem about accessing self-hosted services outside your home network, they create their own issues. Having a public-facing IP address from your home network is never a good idea, even if you know enough to secure it against attack. Any open ports on your home IP address will get sniffed in short order. Source: xda-developers.com … [Read More...]

The developers behind a hit sausage-dueling game hope Steam launch will take it furter

EntertainmentAlready a hit in Japan, the oddball Sausage Legend is primed to go global.Oct 5, 2025, 1:00 PM UTCLife is a series of battles, and I just lost my last one against four gyoza on a skewer. It was an unexpected blow, because honestly, who could have expected me — a springy, respectably proportioned hot dog — to lose against a seemingly inflexible spear of small, unassuming dumplings? … [Read More...]

Audible deal: Get three months for only $3 with this Prime Day discount

The traditional Amazon Prime Day Audible sale has returned for October Prime Day. Audiobook fans can get three months of Audible for just $3, or $1 per month for the first three months. Once the three-month initial period is over, though, the subscription will auto-renew at $14.95 per month.Audible features thousands of titles in its catalog, including podcasts and Audible Originals. Subscribers … [Read More...]

Prime Day Apple deals include 25 percent off a four-pack of AirTags

Prime Day Apple deals can be hard to come by, but right now you can save on one of Apple's smallest (and arguably one if its most useful) gadgets. A four-pack of Apple AirTags is down to $75 right now, which is 24 percent off its usual price. That brings each AirTag in the bundle down to $18.75 each. If you're an Apple user, then the AirTag is the best Bluetooth tracker on the market for … [Read More...]

Scientists Identify Microlightning as Source of Mysterious Blue Marsh Lights

For hundreds of years, people have spun stories of ghostly balls of blue light floating above marshes and swamps, called will-o'-the-wisps or “foolish fire.” They were believed to be ghosts, spirits or tricksters luring people off the right path. Now, a new lab study has tried to determine whether those mysterious embers might actually all begin life as feeble flares, being microlightning that … [Read More...]

This obscure Windows tool has been sitting on your PC for years, and it's still useful

Windows 11 comes loaded with a ton of tools and apps right out of the box. You might call some of it bloat, while others are genuinely useful pieces of software that can help you do basic tasks or keep your PC safe. And others are simply tools you might not even know existed. Source: xda-developers.com … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • NotebookLM’s new Learning Guide feeature completely changed the way I study with the tool
  • Google’s latest Lab experiment is NotebookLM but better
  • The Roku Streaming Stick Plus drops to a new record-low price for Prime Day
  • Apple's AirPods 4 drop to $90 for Prime Day
  • I ditched dynamic DNS for a new-fangled alternative

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023