www.welivesecurity.com New NGate Malware Variant Exploits HandyPay App to Steal NFC Payment Data
Article Content
- •A new NGate variant targets Android users in Brazil by trojanizing the HandyPay app.
- •Malware captures NFC payment data and PINs for fraudulent transactions.
- •The campaign began in November 2025 and uses social engineering for distribution.
ESET Research has identified a new variant of the NGate malware family that targets Android users in Brazil by embedding malicious code in a trojanized version of the HandyPay app. This malware allows attackers to capture NFC payment card data and PINs for unauthorized transactions and ATM withdrawals. The campaign, which began in November 2025, utilizes social engineering tactics to distribute the malicious app through fake lottery websites and a fraudulent Google Play page. The trojanized HandyPay app has never been available on the official Google Play store, and its malicious functionality is designed to evade detection by requiring minimal permissions. Researchers noted that the malware code shows signs of being generated with AI tools, indicating a shift in how cybercriminals develop malware. ESET has shared its findings with Google and the HandyPay developers, who are investigating the misuse of their application. Android users are advised to be cautious about downloading apps from unofficial sources and to utilize Google Play Protect.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Ngate and Caixa Econômica Federal in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Surge in Exploited CVEs and Malware Activity in H1 2026 In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…