PULSE NAME
New NGate variant hides in a trojanized NFC payment app
WHITE AlienVault 2026-04-21 Modified: 2026-04-22
25
IOCs
MEDIUM VOLUME
ESET researchers have identified a new NGate malware variant targeting Android users in Brazil since November 2025. The threat actors trojanized the legitimate HandyPay NFC payment application, likely using AI-generated code, to relay NFC data from victims' payment cards to attacker-controlled devices. The malware enables unauthorized ATM withdrawals and payments while also capturing and exfiltrating payment card PINs to command-and-control servers. Distribution occurs through two channels: a fake Rio de Prêmios lottery website where victims always win a rigged prize, and a fraudulent Google Play page offering a fake card protection app. Both distribution sites are hosted on the same domain. This campaign represents an evolution in NFC-based fraud, with attackers choosing to patch existing legitimate applications rather than using established malware-as-a-service offerings.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
NGate PhantomCard
Indicators of Compromise (25)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 633c3636b646bd08af271584c0e41ff9 2026-04-21
FileHash-MD5 7cecbdfdf2e7a7ae7cc226ae26cd3797 2026-04-21
FileHash-MD5 84361aaf11cde2df075e65fc31082358 2026-04-21
FileHash-MD5 d142bb04f32a50db476b63bbe1ac2ee7 2026-04-21
FileHash-MD5 ea6a6666616f6b02c7b679782a676eab 2026-04-21
FileHash-SHA1 103d78a180eb973b9ffc289e9c53425d29a77229 2026-04-21
FileHash-SHA1 11be9715be9b41b1c8527c9256f0010e26534fdb 2026-04-21
FileHash-SHA1 48a0de6a43fc6e49318ad6873ea63fe325200dbc 2026-04-21
FileHash-SHA1 66de1e0a2e9a421dd16bd54b371558c93e59874f 2026-04-21
FileHash-SHA1 7225ed2cba9cb6c038d8615a47423e45522a9ad1 2026-04-21
FileHash-SHA1 94af94ca818697e1d99123f69965b11ead9f010c 2026-04-21
FileHash-SHA1 a4f793539480677241ef312150e9c02e324c0aa2 2026-04-21
FileHash-SHA1 da84bc78ff2117ddbfdcba4e5c4e3666eea2013e 2026-04-21
FileHash-SHA1 e7ae59cd44204461edbddf292d36eeed38c83696 2026-04-21
FileHash-SHA256 162f8c6bafe0c343c37f173344c4f6880eaec0aea7b491565db874366b161784 2026-04-21
FileHash-SHA256 17a16f08108e25af1c8b058adbaca2cada6a93c2d38c9854148f9e9caac76ac3 2026-04-21
FileHash-SHA256 6e3eea7fb31b8e81026021307247f6eecc5b7f97f35e900796f4786746cde3b8 2026-04-21
FileHash-SHA256 95d906dca5a3be5cf066268662b3c953860e54e9cdcfcd427faf0aaa9cb62bad 2026-04-21
FileHash-SHA256 ddd9e5cfa9e1ddd8d849baef2b487a1608d1695f44c70f246c101de1275887dd 2026-04-21
IPv4 108.165.230.223 2026-04-21
domain protecaocartao.online 2026-04-21
domain raiffeisen-cz.eu 2026-04-21
hostname app.mobil-csob-cz.eu 2026-04-21
hostname nfc.cryptomaker.info 2026-04-21
hostname spy.ngate.cc 2026-04-21