Gbhackers
NFCShare Android Malware Targets Banking Apps to Steal Card Data
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
NFCShare, an Android malware, is spreading through fake updates for legitimate banking apps on GitHub. This malware targets users across Europe, particularly in Italy and Spain, by tricking them into sideloading malicious APKs. Victims are coerced into providing their payment card details via a phishing campaign that mimics real banking processes. Since May 14, 2026, the malware has evolved to include more sophisticated social engineering tactics, including fake verification screens. The malware exploits the NFC chip in mobile devices to extract sensitive information such as card numbers, expiry dates, and PINs. D3Lab researchers first documented NFCShare in January 2026 and have noted its rapid evolution and expanded targeting scope. Security teams have reported that 54% of attacks are successful, with only 14% triggering alerts. Users are advised to download banking apps exclusively from Google Play and remain vigilant against unsolicited verification requests.
Key Points: • NFCShare malware spreads via fake banking app updates on GitHub. • Targets users in Europe, particularly Italy and Spain, through phishing tactics. • Exploits NFC technology to steal sensitive payment card information.