{"id":69273,"date":"2024-08-27T23:25:55","date_gmt":"2024-08-27T23:25:55","guid":{"rendered":"https:\/\/gtechbooster.com\/vine\/?p=69273"},"modified":"2024-08-27T23:25:55","modified_gmt":"2024-08-27T23:25:55","slug":"ngate-android-malware-manages-to-steal-card-data-through-nfc-signal-here-is-how-to-stay-safe","status":"publish","type":"post","link":"https:\/\/gtechbooster.com\/ngate-android-malware-manages-to-steal-card-data-through-nfc-signal-here-is-how-to-stay-safe\/","title":{"rendered":"NGate Android malware manages to steal card data through NFC signal: Here is how to stay safe"},"content":{"rendered":"\n<p>ESET Research researchers have discovered a new Android malware called &#8220;NGate&#8221; that uses the Near Field Communication (NFC) reader on infected smartphones to steal payment card details.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Here&#8217;s how it works:<\/h2>\n\n\n\n<div class=\"gtech-migrated-from-ad-inserter-placement-2\" style=\"text-align: center;\" id=\"gtech-826913912\"><div style=\"margin-right: auto;margin-left: auto;text-align: center;\" id=\"gtech-3123690851\"><a data-bid=\"1\" data-no-instant=\"1\" href=\"https:\/\/gtechbooster.com\/linkout\/17207\" rel=\"noopener\" class=\"notrack\" aria-label=\"26001\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gtechbooster.com\/media\/2023\/01\/26001.jpeg\" alt=\"\"  srcset=\"https:\/\/gtechbooster.com\/media\/2023\/01\/26001.jpeg 1024w, https:\/\/gtechbooster.com\/media\/2023\/01\/26001-768x960.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" width=\"500\" height=\"625\"  style=\"display: inline-block;\" \/><\/a><\/div><\/div><p>Attackers spread the malware through sophisticated phishing schemes, often impersonating banks in SMS and other messaging platforms via messages with links to malicious websites. Once installed, the malware collects the victim&#8217;s banking credentials and guides them to enable NFC on their phone and tap their payment card against the back of the device.<\/p>\n\n\n\n<p>The malware then relays the NFC data from the victim&#8217;s card to the attacker&#8217;s smartphone in real-time. With this stolen data, attackers can create clones of the contactless payment cards and use them to withdraw money from ATMs or make fraudulent purchases.<\/p>\n\n\n\n<p>The malware is based on the open-source NFCGate tool and represents a new attack vector for financial fraud on Android. While it currently targets users in Czechia (Czech Republic), it could easily spread to other countries hence the need to be on the lookout.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><em><strong>Overview of the attack<\/strong><\/em><\/h3>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/gtechbooster.com\/vine\/wp-content\/uploads\/2024\/08\/ngate_android_eset_research.png\" alt=\"NGate Android malware ESET Research\" class=\"wp-image-69277\" style=\"width:750px;height:auto\"\/><figcaption class=\"wp-element-caption\">NGate Android malware ESET Research<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-table is-style-regular\"><table class=\"has-palette-color-14-color has-palette-color-1-background-color has-text-color has-background has-link-color has-fixed-layout\"><thead><tr><th>Name<\/th><th>Gate virus<\/th><\/tr><\/thead><tbody><tr><td><strong>Threat Type<\/strong><\/td><td>Android malware, malicious application<\/td><\/tr><tr><td><strong>Detection Names<\/strong><\/td><td>Avast-Mobile (Android:Evo-gen [Trj]), DrWeb (Android.Banker.NGate.1.origin), ESET-NOD32 (Android\/Spy.NGate.B), Kaspersky (HEUR:Trojan-Banker.AndroidOS.NGate.a), Full List (<a href=\"https:\/\/www.virustotal.com\/gui\/file\/e19a7c8e4994ea4ed680136c9e3a6fff7b82c72f5743952821a446b6cb830f06\/detection\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-palette-color-2-color\">VirusTotal<\/mark><\/a>)<\/td><\/tr><tr><td><strong>Symptoms<\/strong><\/td><td>Malware is designed to stealthily infiltrate the victim&#8217;s computer and remain silent, and thus no particular symptoms are clearly visible on an infected machine.<\/td><\/tr><tr><td><strong>Distribution methods<\/strong><\/td><td>Spam SMSes, infected email attachments, malicious online advertisements, social engineering, deceptive applications, scam websites.<\/td><\/tr><tr><td><strong>Damage<\/strong><\/td><td>Monetary losses, stolen identity (malicious apps might abuse communication apps).<\/td><\/tr><tr><td><strong>Malware Removal (Android)<\/strong><\/td><td>To eliminate possible malware infections, scan your mobile device with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.<\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\">Threat Summary<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">How to stay SAFE<\/h2>\n\n\n\n<p>To stay safe, Android users should:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Only download apps from official app stores like Google Play when you don&#8217;t trust the source.<\/li>\n\n\n\n<li>Be cautious of suspicious URLs and links in messages<\/li>\n\n\n\n<li>Consider turning off NFC when not in use<\/li>\n\n\n\n<li>Use digital wallet versions of cards for added security<\/li>\n\n\n\n<li>Enable Google Play Protect and use antivirus software when you have high chance of contracting it due to your exposure<\/li>\n<\/ul>\n\n\n\n<p class=\"cls has-palette-color-14-color has-palette-color-1-background-color has-text-color has-background has-link-color wp-elements-7d1a7eb0775d542e8fac9a9b866777fb\">As financial malware continues to evolve, it&#8217;s crucial for Android users to stay vigilant and take proactive security measures to protect their payment data from these new threats.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\">More Information \u2139<\/h6>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.eset.com\/int\/about\/newsroom\/press-releases\/research\/eset-research-discovers-ngate-android-malware-which-relays-nfc-traffic-to-steal-victims-cash-from-atms-1\/\">ESET Research discovers NGate: Android malware, which relays NFC traffic to steal victim\u2019s cash from ATMs<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.virustotal.com\/gui\/file\/e19a7c8e4994ea4ed680136c9e3a6fff7b82c72f5743952821a446b6cb830f06\/detection\">NGate Virustotal Detection <\/a><\/li>\n<\/ul>\n<div class=\"gtech-end-cont\" id=\"gtech-1108746633\"><div style=\"margin-right: auto;margin-left: auto;text-align: center;\" id=\"gtech-4292619276\"><a data-bid=\"1\" data-no-instant=\"1\" href=\"https:\/\/gtechbooster.com\/linkout\/17207\" rel=\"noopener\" class=\"notrack\" aria-label=\"26001\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gtechbooster.com\/media\/2023\/01\/26001.jpeg\" alt=\"\"  srcset=\"https:\/\/gtechbooster.com\/media\/2023\/01\/26001.jpeg 1024w, https:\/\/gtechbooster.com\/media\/2023\/01\/26001-768x960.jpeg 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" width=\"500\" height=\"625\"  style=\"display: inline-block;\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Attackers spread the malware through sophisticated phishing schemes, often impersonating banks in SMS and other messaging platforms via messages with links to malicious websites.<\/p>\n","protected":false},"author":7,"featured_media":72523,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2518,8,9],"tags":[64,2106,2459,2107,530,559,1531,2367,949],"class_list":["post-69273","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-payments","category-security","category-tips","tag-android","tag-credit-card","tag-czech-republic","tag-debit-card","tag-malware","tag-mobile-payment","tag-nfc","tag-threat-detection","tag-tutorial"],"blocksy_meta":[],"_links":{"self":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/posts\/69273","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/comments?post=69273"}],"version-history":[{"count":0,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/posts\/69273\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/media\/72523"}],"wp:attachment":[{"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/media?parent=69273"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/categories?post=69273"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gtechbooster.com\/api-json\/wp\/v2\/tags?post=69273"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}