Last seven days
- First activity
- Aug 14, 2026
- Last activity
- Aug 14, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
NFCShare is an Android banking trojan used in financially motivated campaigns that target mobile banking customers in Europe.
Profile source: Mallory opens in a new tabNFCShare
NFCShare is an Android banking trojan used in financially motivated campaigns that target mobile banking customers in Europe. First observed in early 2026 in lures impersonating Deutsche Bank, it later expanded to impersonate multiple banking and payment brands, particularly in Italy and Spain. The malware is typically delivered as a sideloaded malicious APK through phishing pages that mimic legitimate banking portals, shortened links, and fake app-update flows; some campaigns also use SMS messages or phone calls from fake bank representatives to guide victims through enabling installation from unknown sources.
Once installed, NFCShare presents a fraudulent card-verification interface designed to convince victims to place a payment card near the phone and enter the card PIN. It uses Android NFC functionality, including IsoDep and EMV-related commands, to read payment-card data from contactless cards. The malware then exfiltrates the stolen card information and PIN over a WebSocket-based command-and-control channel. The stolen data is intended for payment fraud, including NFC-enabled relay or tap-to-pay abuse.
Operationally, later NFCShare campaigns showed increased scale and discipline, including rapid rebuilding of APKs, rotation of impersonated banking brands, and hosting of payloads in public code repositories disguised as benign projects. Newer samples also used malformed APK packaging intended to disrupt automated extraction and analysis while preserving the malware’s core NFC theft and exfiltration logic. NFCShare has been discussed alongside other Android NFC-focused fraud malware families such as NGate, SuperCard X, and RelayNFC, but it has been assessed as a distinct family with its own code structure and implementation details. The activity is consistent with organized cybercriminal operations focused on banking and payment-card theft.
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.