NGate Malware Trojanizes HandyPay to Steal NFC Card Data

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- ESET researchers discovered a new NGate variant that trojanizes HandyPay—a legitimate NFC relay application—by patching it with code that appears to be AI-generated and capable of capturing and relaying victims' payment card data and PINs to attacker-controlled devices
- The malware campaign, assessed to have begun around November 2025, marks the first NGate attack to single out Brazil, distributing the trojanized app through a fake Rio de Prêmios lottery website and a counterfeit Google Play Store listing for a card protection app
- Victims are socially engineered to set the malicious app as their default payment app, enter their card PIN, and tap their card on the smartphone, at which point attackers can use the stolen NFC data for contactless ATM withdrawals and unauthorized payments
- ESET researcher Lukáš Štefanko said attackers likely chose HandyPay because it natively requires no permissions—reducing suspicion—and offers cheaper subscription pricing than turnkey NFC relay solutions that cost more than $400 per month
- HandyPay has launched an internal investigation; the trojanized version was never made available on the Google Play Store, with attackers relying on direct-download lures instead
- Analysis of the malicious artifact revealed emojis embedded in debug and toast messages, a pattern ESET said is consistent with the use of a large language model to generate or modify source code
Why it matters: This is the first NGate campaign targeting Brazil, and the trojanization of a legitimate app with suspected AI-generated code signals that NFC relay fraud is becoming more accessible to lower-skill attackers. Because HandyPay requires no permissions and undercuts $400-per-month turnkey alternatives, the model gives criminals a cheaper, less suspicious tool for ATM cash-outs—and HandyPay now faces reputational and investigative fallout as the unwitting host.
Ask SkimNews



