www.welivesecurity.com
New NGate Malware Variant Exploits HandyPay App to Steal NFC Payment Data
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
ESET Research has identified a new variant of the NGate malware family that targets Android users in Brazil by embedding malicious code in a trojanized version of the HandyPay app. This malware allows attackers to capture NFC payment card data and PINs for unauthorized transactions and ATM withdrawals. The campaign, which began in November 2025, utilizes social engineering tactics to distribute the malicious app through fake lottery websites and a fraudulent Google Play page. The trojanized HandyPay app has never been available on the official Google Play store, and its malicious functionality is designed to evade detection by requiring minimal permissions. Researchers noted that the malware code shows signs of being generated with AI tools, indicating a shift in how cybercriminals develop malware. ESET has shared its findings with Google and the HandyPay developers, who are investigating the misuse of their application. Android users are advised to be cautious about downloading apps from unofficial sources and to utilize Google Play Protect.
Key Points: • A new NGate variant targets Android users in Brazil by trojanizing the HandyPay app. • Malware captures NFC payment data and PINs for fraudulent transactions. • The campaign began in November 2025 and uses social engineering for distribution.