New NGate Malware Variant Exploits HandyPay App to Steal NFC Payment Data

New NGate Malware Variant Exploits HandyPay App to Steal NFC Payment Data

First seen 21 Apr 2026, 09:24 UTC BleepingcomputerFeeds2.FeedburnerMarkets.BusinessinsiderGbhackersCybersecuritynews+4 86% similarity 69.5

Article Content

Browse articles
ThreatCluster

ESET Research has identified a new variant of the NGate malware family that targets Android users in Brazil by embedding malicious code in a trojanized version of the HandyPay app. This malware allows attackers to capture NFC payment card data and PINs for unauthorized transactions and ATM withdrawals. The campaign, which began in November 2025, utilizes social engineering tactics to distribute the malicious app through fake lottery websites and a fraudulent Google Play page. The trojanized HandyPay app has never been available on the official Google Play store, and its malicious functionality is designed to evade detection by requiring minimal permissions. Researchers noted that the malware code shows signs of being generated with AI tools, indicating a shift in how cybercriminals develop malware. ESET has shared its findings with Google and the HandyPay developers, who are investigating the misuse of their application. Android users are advised to be cautious about downloading apps from unofficial sources and to utilize Google Play Protect.

Key Points: • A new NGate variant targets Android users in Brazil by trojanizing the HandyPay app. • Malware captures NFC payment data and PINs for fraudulent transactions. • The campaign began in November 2025 and uses social engineering for distribution.

ThreatCluster AI

Timeline

2025-11-01
Trojanized HandyPay app distribution campaign begins
2026-04-21
ESET Research publishes findings on new NGate variant
2026-04-21
ESET alerts Google and HandyPay developers about the malware

Community

Browse all →