Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

The Offspring’s Dexter Holland joins Electric Callboy on new single

Lorde’s Gov Ball 2026 setlist features new songs and “Girl, So Confusing”

Black Crowes’ Chris Robinson makes comments on stage

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » NGate campaign targets Brazil, trojanizes HandyPay to steal NFC data and PINs
Celebrities

NGate campaign targets Brazil, trojanizes HandyPay to steal NFC data and PINs

By April 21, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 21, 2026Mobile security/artificial intelligence

Cybersecurity researchers have discovered a new version of an Android malware family called NGate. This version was found to be exploiting a legitimate application called HandyPay instead of NFCGate.

“The attackers obtained an app used to relay NFC data and patched it with malicious code that appears to be AI-generated,” ESET security researcher Lukasz Stefanko said in a report shared with The Hacker News. “Similar to NGate before it, this malicious code allows attackers to transfer NFC data from a victim’s payment card to their own device and use it to make contactless ATM withdrawals and fraudulent payments.”

In addition, the malicious payload could capture the victim’s payment card PIN and leak it to the threat actor’s command and control (C2) server.

NGate, also known as NFSkate, was first publicly documented by a Slovak cybersecurity vendor in August 2024, detailing its ability to carry out relay attacks to siphon victims’ contactless payment data for the purpose of fraudulent transactions.

A year later, Dutch mobile security company ThreatFabric revealed details of a threat codenamed RatOn that uses a dropper app masquerading as an adult version of TikTok and deploys NGate to perform NFC relay attacks.

The latest version of NGate detected by ESET primarily targets users in Brazil, making it the first campaign to name a South American country. The Trojanized HandyPay application is distributed through a website that pretends to be Rio de Prêmios, a lottery run by the Rio de Janeiro state lottery organization, and through a Google Play Store listing page that purports to be a card protection app.

Fake lottery websites try to entice users to tap a button and send a WhatsApp message to claim their winnings. At that point, you will be directed to download a potentially harmful version of the HandyPay app. Regardless of the method used, this app will prompt you to set it as your default payment app after installation.

Victims are then asked to enter their payment card PIN into the app and tap the card on the back of their NFC-enabled smartphone. As soon as this step is executed, the malware exploits HandyPay to capture NFC card data and relay it to an attacker-controlled device. This allows the attacker to use the stolen information to withdraw cash from the ATM.

The active campaign is estimated to have begun around November 2025. The malicious version of HandyPay was never available on the Google Play Store. This means that attackers are using the aforementioned methods as a delivery mechanism to trick unsuspecting users into downloading. HandyPay has since launched an internal investigation into the matter.

ESET noted that HandyPay’s low subscription price may have prompted campaign operators to make the switch rather than continue with their existing turnkey solution, which costs more than $400 per month. “In addition to price, HandyPay natively requires no permissions and can help threat actors avoid arousing suspicion by simply making it the default payment app,” the company noted.

Analysis of the artifacts revealed the presence of emojis in debug and toast messages, highlighting the possibility that large-scale language models (LLMs) were used to generate or modify the source code. Although conclusive evidence remains elusive, this development is consistent with a broader trend of cybercriminals leveraging generative artificial intelligence (AI) to create malware even with little or no technical expertise.

“With the emergence of yet another NGate campaign, it is clear that NFC fraud is on the rise,” ESET said. “This time, instead of using established solutions such as NFCGate and MaaS, which are provided, the attackers decided to trojanize HandyPay, an application with existing NFC relay functionality.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleGoogle patches flaw in Anti-Gravity IDE that allows prompt injection code execution
Next Article How attackers get in through your front door via identity-based attacks

Related Posts

Princess Charlene of Monaco is enthusiastic about Monaco F1 Grand Prix

June 5, 2026

Queen Camilla wears Queen Elizabeth’s Diamond Star Brooch

June 5, 2026

Emily Blunt wears custom Stella McCartney to Disclosure Day in London

June 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The Offspring’s Dexter Holland joins Electric Callboy on new single

Lorde’s Gov Ball 2026 setlist features new songs and “Girl, So Confusing”

Black Crowes’ Chris Robinson makes comments on stage

Top 10 Pop, Rock, and Country Concerts of the Summer – Plus Jazz and Classical

Trending Posts

The Offspring’s Dexter Holland joins Electric Callboy on new single

June 6, 2026

Lorde’s Gov Ball 2026 setlist features new songs and “Girl, So Confusing”

June 6, 2026

Black Crowes’ Chris Robinson makes comments on stage

June 6, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.