Android malware turns phones into malicious tap-to-pay machines https://www.malwarebytes.com/blog/news/2025/04/android-malware-turns-phones-into-malicious-tap-to-pay-machines #Uncategorized #Android #malware #News #nfc

Android malware turns phones into malicious tap-to-pay machines https://www.malwarebytes.com/blog/news/2025/04/android-malware-turns-phones-into-malicious-tap-to-pay-machines #Uncategorized #Android #malware #News #nfc
Chinese Cybercriminals Released Z-NFC Tool for Payment Fraud – Source: securityaffairs.com https://ciso2ciso.com/chinese-cybercriminals-released-z-nfc-tool-for-payment-fraud-source-securityaffairs-com/ #rssfeedpostgeneratorecho #informationsecuritynews #ITInformationSecurity #SecurityAffairscom #CyberSecurityNews #PierluigiPaganini #SecurityAffairs #BreakingNews #SecurityNews #hackingnews #CyberCrime #Cybercrime #DarkWeb #DeepWeb #hacking #NFC
Hat jemand von euch eine Volksbank Debitkarte und die NFC (kontaktlos bezahlen) Funktion deaktiviert und nach einigen Bezahlvorgängen ist die Karte "tot"? Terminals zeigen "kein Chip", der ChipTAN Kartenleser zeigt "Fehler 0", beides Anzeichen dafür, dass keine (drahtgebundene-) Kommunikation mehr mit dem Chip möglich ist.
Die VoBa schickt dann eine neue Karte (für die sie 10€ will) und zwei Monate später das gleiche Spiel...
Samsung Wallet si Prepara a Conquistare i Pagamenti: In Arrivo Rateizzazione e Trasferimenti di Denaro NFC: Samsung Wallet si appresta a diventare un hub finanziario ancora più completo e competitivo, integrando due funzionalità molto richieste: il pagamento rateale (spesso indicato con l’acronimo BNPL, Buy Now, Pay Later) e la possibilità di effettuare trasferimenti di denaro peer-to-peer (P2P) tramite tecnologia NFC. Queste novità,… https://pianetatecnologia.it/samsung-wallet-si-prepara-a-conquistare-i-pagamenti-in-arrivo-rateizzazione-e-trasferimenti-di-denaro-nfc/?utm_source=dlvr.it&utm_medium=mastodon #SamsungWallet #Pagamenti #NFC
Chinese Cybercriminals Released Z-NFC Tool for Payment Fraud
https://securityaffairs.com/176829/cyber-crime/chinese-cybercriminals-released-z-nfc-tool-for-payment-fraud.html
#securityaffairs #hacking #NFC
AFH : I have NFC problems with an iPhone 13. It is not totally dead as it works with some Apple Pay payments (but not with all terminals) and doesn't work at all with other services (French ID card and Paris public transportation pass reading), so it appears weak more than entirely off. Apple cannot help for now because they do not see any problem. I tried resetting the phone entirely, in vain. If someone ever faced this issue, I'm all ears
#askForHelp #iPhone #NFC #iOS #ApplePay #mastoHelp
Malware chino SuperCard X para Android es capaz de automatizar ataques de retransmisión NFC https://blog.elhacker.net/2025/04/malware-chino-supercard-x-para-android.html #android #china #relay #NFC
SuperCard X: nuova minaccia contactless in rapida espansione
https://gomoot.com/supercard-x-nuova-minaccia-contactless-in-rapida-espansione
Ricevi un SMS dalla banca e ti chiedono di “verificare la carta”? Attento: potrebbe essere SuperCard X.
Un’app fraudolenta legge la tua carta via NFC e la usa da remoto.
Ecco come funziona https://www.d3lab.net/supercard-x-la-nuova-truffa-che-colpisce-gli-utenti-italiani/
In Italia è attiva una nuova frode via app Android: SuperCard X sfrutta NFC per clonare carte contactless.
Smishing + Vishing + App fake = pagamenti illeciti in tempo reale.
Analisi completa https://www.d3lab.net/supercard-x-la-nuova-truffa-che-colpisce-gli-utenti-italiani/
A new Android malware campaign is using NFC relay attacks to clone credit cards — and it’s nearly invisible to antivirus tools.
Security researchers have discovered 'SuperCard X', a malware-as-a-service (MaaS) platform that allows cybercriminals to steal card data and make contactless payments using compromised Android devices.
Key highlights from the report:
- Distributed via social engineering scams through fake SMS or WhatsApp messages
- Victims are tricked into installing a malicious app disguised as a bank “verification” tool
- Once installed, it uses NFC to read card chip data and sends it to a second attacker device
- Attackers use a companion app to emulate the victim’s card and make payments or ATM withdrawals
What makes it dangerous:
- SuperCard X requests minimal permissions, making it hard to detect
- It uses ATR-based card emulation and mutual TLS (mTLS) for secure communication
- Malware is not flagged by any antivirus engines on VirusTotal
- Transactions are small, instant, and look legitimate to banks — making them harder to detect or reverse
Google responded saying Play Protect is active and currently no such apps are listed on Google Play. But since these apps spread outside the store, Android users remain at risk — especially if they sideload apps or fall for impersonation scams.
This is a textbook example of how mobile payment infrastructure is being exploited — and why NFC security deserves more attention in mobile-first threat models.
At @Efani we’re committed to helping protect high-risk users from silent, evasive mobile threats just like this.
Seriously, these NFC relay attacks are getting nasty! It's frighteningly easy for crooks to just swipe your money using NFC these days. And now? There's some fresh Android malware making it even simpler for them.
This particular one, "SuperCard X," is currently going after banks over in Italy. But let's be real, this kind of scam can pop up absolutely anywhere. It's a global issue.
So, here’s the lowdown on their method: it often starts with smishing texts or maybe some sketchy phone calls. They trick you into installing malware. Then, the moment you tap your phone at a payment terminal, BAM – they grab your card data right then and there. Pretty sneaky, right?
As a pentester, I unfortunately run into stuff like this more often than you'd think. That’s why I'm putting this out there: you've gotta be careful! Always double-check the apps you install, make sure Google Play Protect is actually turned on, and please, don't trust those weird, unexpected calls asking for info!
What about you? What steps are you taking to keep your mobile payments secure? Drop your thoughts below!
New sophisticate #malware #SuperCard X targets #Androids via #NFC relay Attacks
https://securityaffairs.com/176737/malware/supercard-x-a-new-sophisticate-malware-targets-androids-via-nfc-relay-attacks.html
#securityaffairs #hacking
New sophisticate #malware #SuperCard X targets #Androids via #NFC relay Attacks
https://securityaffairs.com/176737/malware/supercard-x-a-new-sophisticate-malware-targets-androids-via-nfc-relay-attacks.html
#securityaffairs #hacking
TIL: "Das bargeldlose Bezahlen hat - im Schnitt über alle Parkscheinautomaten im Stadtgebiet -
mittlerweile einen Anteil von circa 45 % der Einnahmen erreicht."
https://web1.karlsruhe.de/ris/oparl/bodies/0001/downloadfiles/00664491.pdf