NFCShare Android Malware Targets Banking Apps to Steal Card Data

NFCShare Android Malware Targets Banking Apps to Steal Card Data

First seen 9 Jun 2026, 06:56 UTC BleepingcomputerGbhackersCybersecuritynewsTribune.PhSunstar.Ph+1 88% similarity 67.5

Article Content

Browse articles
ThreatCluster

NFCShare, an Android malware, is spreading through fake updates for legitimate banking apps on GitHub. This malware targets users across Europe, particularly in Italy and Spain, by tricking them into sideloading malicious APKs. Victims are coerced into providing their payment card details via a phishing campaign that mimics real banking processes. Since May 14, 2026, the malware has evolved to include more sophisticated social engineering tactics, including fake verification screens. The malware exploits the NFC chip in mobile devices to extract sensitive information such as card numbers, expiry dates, and PINs. D3Lab researchers first documented NFCShare in January 2026 and have noted its rapid evolution and expanded targeting scope. Security teams have reported that 54% of attacks are successful, with only 14% triggering alerts. Users are advised to download banking apps exclusively from Google Play and remain vigilant against unsolicited verification requests.

Key Points: • NFCShare malware spreads via fake banking app updates on GitHub. • Targets users in Europe, particularly Italy and Spain, through phishing tactics. • Exploits NFC technology to steal sensitive payment card information.

ThreatCluster AI

Timeline

2026-01-01
NFCShare malware first documented
D3Lab researchers identified NFCShare as a new Android malware targeting Deutsche Bank customers.
BleepingComputer
2026-04-10
GitHub repository created for NFCShare
The repository began hosting malicious APKs impersonating banking apps, with 56 unique APKs identified.
BleepingComputer
2026-05-14
New wave of NFCShare attacks observed
The malware campaign expanded its targeting to include multiple banks in Italy and Spain, using refined social engineering tactics.
Gbhackers
2026-06-08
BleepingComputer reports on NFCShare evolution
The malware's new variants include malformed APK packaging to hinder automated analysis, complicating detection efforts.
BleepingComputer
2026-06-09
Gbhackers and Cybersecuritynews report on NFCShare
Both outlets highlight the ongoing threat posed by NFCShare, emphasizing its sophisticated phishing methods and widespread impact.
Gbhackers

Community

Browse all →