Massive surge of NFC relay malware steals Europeans’ credit cards
嗯,用户让我帮忙总结一下这篇文章的内容,控制在100个字以内,而且不需要用“文章内容总结”之类的开头,直接写描述。首先,我需要仔细阅读文章,抓住主要信息。 文章讲的是NFC中继恶意软件在东欧的流行情况,过去几个月发现了超过760个恶意Android应用。这些应用利用HCE技术窃取支付卡信息。传统银行木马通过覆盖层或远程工具窃取信息,而NFC恶意软件则不同,它通过捕获EMV字段、响应APDU命令或转发请求到远程服务器来实现。 首次出现是在2023年波兰,后来扩散到捷克和俄罗斯。变种包括数据收集器、中继工具包、“幽灵点击”支付和伪装银行应用。Zimperium公司指出这种恶意软件在东欧迅速增长,并且已经影响了多个地区。 建议用户不要安装未知来源的APK,检查权限,并使用Play Protect扫描设备。 总结的时候要简洁明了,涵盖NFC恶意软件的增长、技术手段、首次出现时间和扩散情况,以及安全建议。控制在100字以内,所以需要精简语言。 </think> NFC中继恶意软件在东欧迅速蔓延,过去几个月发现超760个恶意Android应用利用HCE技术窃取支付卡信息。这些恶意软件通过捕获EMV字段、响应APDU命令或转发请求到远程服务器实现攻击。首次出现于2023年波兰,并扩散至捷克和俄罗斯等地。建议用户避免安装未知来源的APK,并启用Play Protect扫描设备以防范威胁。 2025-10-30 20:30:19 Author: www.bleepingcomputer.com(查看原文) 阅读量:6 收藏

Credit cards

Near-Field Communication (NFC) relay malware has grown massively popular in Eastern Europe, with researchers discovering over 760 malicious Android apps using the technique to steal people's payment card information in the past few months.

Contrary to the traditional banking trojans that use overlays to steal banking credentials or remote access tools to perform fraudulent transactions, NFC malware abuses Android's Host Card Emulation (HCE) to emulate or steal contactless credit card and payment data.

They capture EMV fields, respond to APDU commands from a POS terminal with attacker-controlled replies, or forward terminal requests to a remote server, which crafts the proper APDU responses to enable payments at the terminal without the physical cardholder present.

The technique was spotted in the wild for the first time in 2023 in Poland, followed by campaigns in the Czech Republic, and later, more massive attack waves in Russia.

Over time, multiple variants emerged following different practical approaches, including:

  • Data harvesters that exfiltrate EMV fields to Telegram or other endpoints,
  • Relay toolkits that forward APDUs to remote paired devices,
  • "Ghost-tap" payments where HCE responses are manipulated to authorize POS transactions in real time,
  • and PWAs or fake bank apps that are registered as the default payment handler on Android.

According to mobile security firm Zimperium, a member of Google's 'App Defense Alliance,' the popularity of NFC malware on Android has exploded lately, particularly in Eastern Europe.

"What began as just a few isolated samples has now expanded to more than 760 malicious apps observed in the wild—demonstrating that NFC relay abuse is not slowing down but continuing to accelerate," explains Zimperium.

"Campaigns previously documented by other vendors are now broadening their reach to additional regions, including Russia, Poland, the Czech Republic, Slovakia, and others."

NFC malware samples caught in the wild
NFC malware samples caught in the wild
Source: Zimperium

The firm has identified over 70 command-and-control (C2) servers and app distribution hubs supporting these campaigns, as well as dozens of Telegram bots and private channels used to exfiltrate stolen data or coordinate operations.

The apps used to distribute the malware impersonate Google Pay or financial institutions such as Santander Bank, VTB Bank, Tinkoff Bank, ING Bank, Bradesco Bank, Promsvyazbank (PSB), and several others.

Interface of some of the malicious apps
Interface of some of the malicious apps
Source: Zimperium

Android users are advised to never install APKs from outside Google Play unless they explicitly trust the publisher, only install banking apps from the official bank links, and check for suspicious permissions, such as NFC access or foreground service privileges.

Additionally, it is recommended to regularly scan your device with Play Protect, Android's built-in anti-malware tool, and to disable NFC if not needed.

The complete list of the APKs Zimperium discovered in the wild is available here.


文章来源: https://www.bleepingcomputer.com/news/security/massive-surge-of-nfc-relay-malware-steals-europeans-credit-cards/
如有侵权请联系:admin#unsafe.sh