news.mlab.sh
Back to the feed
malware

New NGate variant hides in a trojanized NFC payment app

High
Summary

A new variant of the NGate malware, dubbed NGate, is targeting Android users in Brazil by abusing the legitimate HandyPay app. Threat actors used generative AI to modify HandyPay, allowing them to steal NFC data, including payment card PINs, and conduct unauthorized transactions. The campaign, ongoing since November 2025, utilizes fake lottery and Google Play websites for distribution and highlights the growing sophistication of NFC-based attacks and the use of malware-as-a-service.

Read the full article at WeLiveSecurity

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.