Skip to content

NFCShare

NFCShare is an Android banking trojan used in financially motivated campaigns that target mobile banking customers in Europe.

Profile source: Mallory opens in a new tab

NFCShare

Family profile

NFCShare is an Android banking trojan used in financially motivated campaigns that target mobile banking customers in Europe. First observed in early 2026 in lures impersonating Deutsche Bank, it later expanded to impersonate multiple banking and payment brands, particularly in Italy and Spain. The malware is typically delivered as a sideloaded malicious APK through phishing pages that mimic legitimate banking portals, shortened links, and fake app-update flows; some campaigns also use SMS messages or phone calls from fake bank representatives to guide victims through enabling installation from unknown sources.

Once installed, NFCShare presents a fraudulent card-verification interface designed to convince victims to place a payment card near the phone and enter the card PIN. It uses Android NFC functionality, including IsoDep and EMV-related commands, to read payment-card data from contactless cards. The malware then exfiltrates the stolen card information and PIN over a WebSocket-based command-and-control channel. The stolen data is intended for payment fraud, including NFC-enabled relay or tap-to-pay abuse.

Operationally, later NFCShare campaigns showed increased scale and discipline, including rapid rebuilding of APKs, rotation of impersonated banking brands, and hosting of payloads in public code repositories disguised as benign projects. Newer samples also used malformed APK packaging intended to disrupt automated extraction and analysis while preserving the malware’s core NFC theft and exfiltration logic. NFCShare has been discussed alongside other Android NFC-focused fraud malware families such as NGate, SuperCard X, and RelayNFC, but it has been assessed as a distinct family with its own code structure and implementation details. The activity is consistent with organized cybercriminal operations focused on banking and payment-card theft.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 14, 2026
Last activity
Aug 14, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • NL1

Leading providers

  • Mynymbox Hosting LLC1

Infrastructure traits

  • Hosting 1

MITRE ATT&CK

NFCShare in ATT&CK

13 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.