Gbhackers NFCShare Android Malware Targets Banking Apps to Steal Card Data
Article Content
- •NFCShare malware spreads via fake banking app updates on GitHub.
- •Targets users in Europe, particularly Italy and Spain, through phishing tactics.
- •Exploits NFC technology to steal sensitive payment card information.
NFCShare, an Android malware, is spreading through fake updates for legitimate banking apps on GitHub. This malware targets users across Europe, particularly in Italy and Spain, by tricking them into sideloading malicious APKs. Victims are coerced into providing their payment card details via a phishing campaign that mimics real banking processes. Since May 14, 2026, the malware has evolved to include more sophisticated social engineering tactics, including fake verification screens. The malware exploits the NFC chip in mobile devices to extract sensitive information such as card numbers, expiry dates, and PINs. D3Lab researchers first documented NFCShare in January 2026 and have noted its rapid evolution and expanded targeting scope. Security teams have reported that 54% of attacks are successful, with only 14% triggering alerts. Users are advised to download banking apps exclusively from Google Play and remain vigilant against unsolicited verification requests.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track NFCShare and Deutsche Bank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Surge in Exploited CVEs and Malware Activity in H1 2026 In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…