NFCShare Android malware spreads via fake banking app updates on GitHub
A new variant of the NFCShare Android malware is spreading through fake updates for banking apps hosted on GitHub, targeting financial institutions across Europe. The malware leverages NFC technology to steal payment card data, including card numbers and PINs, and exfiltrates this information to attacker command-and-control servers. This campaign highlights the evolving tactics of threat actors exploiting mobile banking vulnerabilities.
The recent surge in NFCShare attacks, beginning May 14th, involves victims visiting phishing sites mimicking legitimate banks and being directed to a GitHub repository containing a malicious APK file. This file, disguised as an update for a banking app, then tricks users into scanning their NFC cards, allowing the malware to steal sensitive payment information. Researchers at D3Lab have been tracking the malware's evolution since January 2026, noting its distinct code and architecture while acknowledging a potential connection to existing NFC-based malware campaigns. The latest version incorporates a technique to hinder automated analysis by using malformed APK packaging, disrupting static analysis tools without preventing manual investigation.