Friday, 14 March 2025
27.2 C
Singapore
28.2 C
Thailand
20.6 C
Indonesia
26.9 C
Philippines

ESET unveils NGate: Android malware used in Czech ATM fraud

Discover how NGate, a new Android malware, relays NFC data to clone ATM cards and facilitate unauthorised withdrawals, as uncovered by ESET Research.

ESET Research has identified a novel form of Android malware known as NGate, which has been utilised to carry out sophisticated attacks on customers of three Czech banks. This malware uniquely captures and relays NFC traffic, enabling attackers to withdraw cash from ATMs by cloning the data from victims’ payment cards.

Detailed operation of NGate

NGate infiltrates Android devices through a malicious app that deceives users into believing they are responding to legitimate security concerns from their bank. Once installed, it enables criminals to capture NFC data from the victim’s payment card and transmit it to an attacker-controlled device. This setup allows the replication of the victimโ€™s card, facilitating cash withdrawals from ATMs without the need for physical access to the card or rooting the victimโ€™s device.

Lukรกลก ล tefanko of ESET elucidated the operation, saying, “We haven’t seen this novel NFC relay technique in any previously discovered Android malware. The technique is based on a tool called NFCGate, designed by students at the Technical University of Darmstadt, Germany, to capture, analyse, or alter NFC traffic; therefore, we named this new malware family NGate.”

Victims were duped into installing NGate via deceptive SMS messages that falsely alerted them about a compromised device due to a tax issue and urged them to install a linked application. Crucially, NGate was never available on the official Google Play store.

Prevention and implications

The malware campaign began in November 2023 and involved domains impersonating legitimate banking platforms. It was part of a broader phishing strategy that included using progressive web apps and WebAPKs to distribute malicious content. By March 2024, following the arrest of a suspect linked to these activities, the spread of NGate had been curtailed.

ESET Research advises the public to adopt proactive security measures to mitigate the risk of such advanced threats. Ensuring security involves checking website URLs, downloading apps only from trusted sources, keeping PIN codes secret, using security apps on smartphones, turning off NFC when not in use, employing protective cases, and opting for virtual cards that require authentication.

Hot this week

Meta introduces new fact-checking system for Facebook, Instagram, and Threads

Meta is launching Community Notes on Facebook, Instagram, and Threads in the US on March 18, aiming to improve fact-checking with a crowdsourced system.

Tammy Nam takes the helm as CEO of AI-driven ad startup Creatopy

Tammy Nam joins AI-powered ad startup Creatopy as CEO, bringing experience from PicsArt and Viki. The company reports a 400% revenue growth.

Singapore Airlines and Scoot to ban in-flight power bank charging from April 1

Singapore Airlines and Scoot will ban in-flight power bank use from April 1 due to safety concerns over battery fires. Check their new policies here.

X experiences repeated outages amid cyberattack claims

X faces repeated outages, with Elon Musk blaming a cyberattack. Users report global disruptions while alternative platforms remain stable.

Microsoft expands AI Pinnacle Program with new industry partnerships in Singapore

Microsoft expands its AI Pinnacle Program in Singapore with new industry partnerships, AI research collaborations, and initiatives to upskill local talent.

OpenAI calls DeepSeek โ€˜state-controlledโ€™ and urges bans on Chinese AI models

OpenAI calls DeepSeek โ€œstate-controlledโ€ and urges bans on PRC-backed AI models, citing security concerns and risks of data sharing under Chinese law.

Meta introduces new fact-checking system for Facebook, Instagram, and Threads

Meta is launching Community Notes on Facebook, Instagram, and Threads in the US on March 18, aiming to improve fact-checking with a crowdsourced system.

OpenAI pushes for clear copyright rules in AI development

OpenAI urges the US government to protect AI training under "fair use," sparking debate over copyright laws and AI development.

Singapore Airlines and Scoot to ban in-flight power bank charging from April 1

Singapore Airlines and Scoot will ban in-flight power bank use from April 1 due to safety concerns over battery fires. Check their new policies here.

Related Articles