Executive Summary
In early 2024, cybersecurity researchers uncovered a sweeping campaign across Eastern Europe involving over 760 malicious Android apps leveraging NFC (Near-Field Communication) relay malware. Threat actors distributed these apps through unofficial channels, targeting unsuspecting users to intercept and relay credit card information during contactless transactions. Once installed, the malware exploited device-level NFC permissions to steal payment credentials, enabling attackers to commit significant financial fraud and undermine consumer trust in mobile payments. The primary impact has been large-scale theft from compromised cards, increased banking fraud, regulatory concern, and widespread consumer exposure.
This incident signals a sharp escalation in mobile payment threats and demonstrates how sophisticated cybercriminals now target embedded hardware features. Organizations face new challenges in defending against evolving mobile malware, with compliance and security standards coming under increased scrutiny.
Why This Matters Now
The surge in NFC relay malware illustrates how quickly attackers adapt to new payment technologies. As businesses and individuals increasingly rely on contactless payments, the rapid proliferation of such sophisticated malware exposes both users and institutions to significant financial and reputational risks. Timely action is essential to protect digital payments and maintain consumer confidence.
Attack Path Analysis
Attackers delivered malicious Android apps to victims, leading to device compromise via user installation. Once installed, the malware abused permissions and exploited Android OS weaknesses to gain higher privileges. The malware then established persistence and, possibly, accessed sensitive areas of the device to facilitate further malicious activity. Command and control channels were established to receive remote attacker instructions and deliver stolen data. Payment card data and credentials captured via NFC relay were exfiltrated over network channels. The impact was significant financial theft, victim data exposure, and potential ongoing risk to user accounts.
Kill Chain Progression
Initial Compromise
Description
Victims unknowingly installed malicious NFC relay apps from untrusted sources, granting initial access to devices.
Related CVEs
CVE-2025-48612
CVSS 7.8A vulnerability in Android allows an application on a work profile to improperly set the main user's default NFC payment setting through inadequate input validation.
Affected Products:
Google Android – All versions prior to December 2025 security patch
Exploit Status:
no public exploitReferences:
MITRE ATT&CK® Techniques
Deliver Malicious App via Authorized App Store
Obtain Device Information
Credential Access via Input Capture
Access Sensitive Data in Device Storage
Masquerade as Legitimate Application
Exfiltration Over Alternative Protocol
Credential Stealing via Network Communication
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Prevent Common Malware Attacks
Control ID: 6.4.3
PCI DSS 4.0 – Strong Authentication for Payment Devices
Control ID: 8.2.1
NIS2 Directive – Incident Handling and Reporting
Control ID: Article 21(2)(d)
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: Section 500.02
CISA ZTMM 2.0 – Mobile Device Threat Detection and Management
Control ID: Device Security: Mobile Device Posture
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Mobile malware targeting NFC payment cards creates direct financial fraud exposure, requiring enhanced egress security and threat detection capabilities for payment processing systems.
Banking/Mortgage
NFC relay attacks compromise contactless payment infrastructure, demanding zero trust segmentation and encrypted traffic protection to prevent credit card data theft and unauthorized transactions.
Retail Industry
Consumer-facing NFC payment terminals vulnerable to relay malware attacks, necessitating multicloud visibility and anomaly detection to protect customer transaction data and payment processing.
Consumer Electronics
Android devices serving as attack vectors for NFC relay malware require enhanced mobile security policies and threat detection to prevent payment card information compromise.
Sources
- Massive surge of NFC relay malware steals Europeans’ credit cardshttps://www.bleepingcomputer.com/news/security/massive-surge-of-nfc-relay-malware-steals-europeans-credit-cards/Verified
- ESET Research discovers NGate: Android malware, which relays NFC traffic to steal victim’s cash from ATMshttps://www.eset.com/us/about/newsroom/research/eset-research-discovers-ngate-android-malware-which-relays-nfc-traffic-to-steal-victims-cash-from-atms-1/Verified
- Over 760 malicious NFC apps for Android active in Eastern Europehttps://hackmag.com/news/nfc-relay-malwareVerified
- SuperCard X: Android malware uses NFC to steal credit cardshttps://www.incibe.es/en/incibe-cert/publications/cybersecurity-highlights/supercard-x-android-malware-uses-nfc-steal-credit-cardsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, egress controls, encrypted traffic enforcement, and continuous anomaly detection would have substantially limited or detected the malware’s ability to move data off device and communicate with C2 infrastructure. These CNSF controls could prevent unauthorized internal communication and policy violations while revealing anomalous exfiltration or authentication attempts.
Control: Threat Detection & Anomaly Response
Mitigation: Early identification of suspicious app or behavior on endpoints or networks.
Control: Threat Detection & Anomaly Response
Mitigation: Alerts on abnormal permission requests or privilege escalation attempts.
Control: East-West Traffic Security
Mitigation: Prevents unauthorized internal communications or data access between workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks or alerts on connections to known malicious domains or suspicious outbound traffic.
Control: Encrypted Traffic (HPE) & Egress Security
Mitigation: Detects and blocks data exfiltration over network channels, even if attempted in the clear.
Rapid detection and response to data loss or account compromise limiting damage.
Impact at a Glance
Affected Business Functions
- Payments
- Point-of-Sale Transactions
- ATM Withdrawals
Estimated downtime: 5 days
Estimated loss: $5,000,000
Potential exposure of sensitive payment card information, including card numbers, expiration dates, and security codes, leading to unauthorized transactions and financial fraud.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce egress and C2 communications policy controls to prevent unauthorized connections from mobile devices or cloud workloads.
- • Enable real-time threat detection and baselining to spot abnormal new app installs, privilege escalation, and network behaviors.
- • Deploy East-West microsegmentation to restrict app-to-app and service-to-service communications, minimizing lateral exposure within environments.
- • Mandate encryption for all sensitive or regulated data in transit to block exfiltration and packet sniffing risks.
- • Centralize multicloud visibility and incident response to rapidly detect, investigate, and contain malware-driven financial fraud.



