NGate
NGate is an Android malware family used in NFC relay fraud against banking customers.
NGate
Family profile
NGate is an Android malware family used in NFC relay fraud against banking customers. It is designed to capture or relay contactless payment card data from a victim’s physical card through an infected Android device and enable unauthorized contactless purchases or ATM cash withdrawals. The malware has been associated with campaigns targeting users in Europe, including Poland and the Czech Republic, and later Brazil.
Early NGate activity was built around code derived from the NFCGate research project and was distributed through bank-impersonation lures. Victims were socially engineered into installing a malicious Android application outside the official app store, then instructed to place a payment card near the phone and enter the card PIN under the pretense of verification or security checks. The malware relayed NFC communication in real time to attacker-controlled infrastructure, a requirement for abusing dynamic transaction data used in contactless payments. In these campaigns, the malicious apps also included functionality to collect and transmit the victim’s PIN.
Later variants evolved to abuse trojanized legitimate NFC relay software rather than relying solely on NFCGate-derived tooling. A notable NGate variant embedded malicious code into the legitimate Android app HandyPay and targeted users in Brazil. This version was distributed via fake lottery-themed websites, spoofed app-store pages, and WhatsApp-guided social engineering. After installation, it asked to be set as the default payment application, prompted the victim to enter a payment card PIN, and instructed the victim to tap the physical card to the device. The malware then forwarded NFC payment data to an attacker-controlled device and exfiltrated the PIN, enabling fraudulent payments and contactless ATM withdrawals.
NGate is widely characterized as Android NFC relay malware and has also been described as an Android banker in some reporting because of its direct role in financial theft. It is part of a broader trend of mobile malware families abusing NFC for payment fraud, alongside families such as SuperCard X, RelayNFC, and related threats. Reporting has also noted signs that some newer NGate code may have been generated or modified with AI assistance, although definitive proof of that development method is not available.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Spoofing
Samples
Recent samples
2 sandbox samples in the Derp library, newest 2 shown
MITRE ATT&CK