malware
New NGate variant hides in a trojanized NFC payment app
High
Summary
A new variant of the NGate malware, dubbed NGate, is targeting Android users in Brazil by abusing the legitimate HandyPay app. Threat actors used generative AI to modify HandyPay, allowing them to steal NFC data, including payment card PINs, and conduct unauthorized transactions. The campaign, ongoing since November 2025, utilizes fake lottery and Google Play websites for distribution and highlights the growing sophistication of NFC-based attacks and the use of malware-as-a-service.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data