Skip to content
NFCShare Android Malware Targets Banking Apps to Steal Card Data

NFCShare Android Malware Targets Banking Apps to Steal Card Data

First seen 9 Jun 2026, 06:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 10, 2026 at 06:30 UTC
  • NFCShare malware spreads via fake banking app updates on GitHub.
  • Targets users in Europe, particularly Italy and Spain, through phishing tactics.
  • Exploits NFC technology to steal sensitive payment card information.

NFCShare, an Android malware, is spreading through fake updates for legitimate banking apps on GitHub. This malware targets users across Europe, particularly in Italy and Spain, by tricking them into sideloading malicious APKs. Victims are coerced into providing their payment card details via a phishing campaign that mimics real banking processes. Since May 14, 2026, the malware has evolved to include more sophisticated social engineering tactics, including fake verification screens. The malware exploits the NFC chip in mobile devices to extract sensitive information such as card numbers, expiry dates, and PINs. D3Lab researchers first documented NFCShare in January 2026 and have noted its rapid evolution and expanded targeting scope. Security teams have reported that 54% of attacks are successful, with only 14% triggering alerts. Users are advised to download banking apps exclusively from Google Play and remain vigilant against unsolicited verification requests.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 93d ago How this analysis works

Timeline

2026-01-01
NFCShare malware first documented
D3Lab researchers identified NFCShare as a new Android malware targeting Deutsche Bank customers.
BleepingComputer
2026-04-10
GitHub repository created for NFCShare
The repository began hosting malicious APKs impersonating banking apps, with 56 unique APKs identified.
BleepingComputer
2026-05-14
New wave of NFCShare attacks observed
The malware campaign expanded its targeting to include multiple banks in Italy and Spain, using refined social engineering tactics.
Gbhackers
2026-06-08
BleepingComputer reports on NFCShare evolution
The malware's new variants include malformed APK packaging to hinder automated analysis, complicating detection efforts.
BleepingComputer
2026-06-09
Gbhackers and Cybersecuritynews report on NFCShare
Both outlets highlight the ongoing threat posed by NFCShare, emphasizing its sophisticated phishing methods and widespread impact.
Gbhackers

More articles in this cluster (7)

Following this threat?

Track NFCShare and Deutsche Bank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed