Saturday, 1 February 2025
25.8 C
Singapore
23.1 C
Thailand
20.8 C
Indonesia
26 C
Philippines

ESET unveils NGate: Android malware used in Czech ATM fraud

Discover how NGate, a new Android malware, relays NFC data to clone ATM cards and facilitate unauthorised withdrawals, as uncovered by ESET Research.

ESET Research has identified a novel form of Android malware known as NGate, which has been utilised to carry out sophisticated attacks on customers of three Czech banks. This malware uniquely captures and relays NFC traffic, enabling attackers to withdraw cash from ATMs by cloning the data from victims’ payment cards.

Detailed operation of NGate

NGate infiltrates Android devices through a malicious app that deceives users into believing they are responding to legitimate security concerns from their bank. Once installed, it enables criminals to capture NFC data from the victim’s payment card and transmit it to an attacker-controlled device. This setup allows the replication of the victim’s card, facilitating cash withdrawals from ATMs without the need for physical access to the card or rooting the victim’s device.

Lukáš Å tefanko of ESET elucidated the operation, saying, “We haven’t seen this novel NFC relay technique in any previously discovered Android malware. The technique is based on a tool called NFCGate, designed by students at the Technical University of Darmstadt, Germany, to capture, analyse, or alter NFC traffic; therefore, we named this new malware family NGate.”

Victims were duped into installing NGate via deceptive SMS messages that falsely alerted them about a compromised device due to a tax issue and urged them to install a linked application. Crucially, NGate was never available on the official Google Play store.

Prevention and implications

The malware campaign began in November 2023 and involved domains impersonating legitimate banking platforms. It was part of a broader phishing strategy that included using progressive web apps and WebAPKs to distribute malicious content. By March 2024, following the arrest of a suspect linked to these activities, the spread of NGate had been curtailed.

ESET Research advises the public to adopt proactive security measures to mitigate the risk of such advanced threats. Ensuring security involves checking website URLs, downloading apps only from trusted sources, keeping PIN codes secret, using security apps on smartphones, turning off NFC when not in use, employing protective cases, and opting for virtual cards that require authentication.

Hot this week

DeepSeek overtakes ChatGPT as the No. 1 app on the App Store

DeepSeek surges past ChatGPT as the No. 1 app, revolutionising AI with efficient training methods and global appeal while facing challenges.

Pentagon moves to block DeepSeek after staff access Chinese servers

The Pentagon is blocking DeepSeek after employees unknowingly connected work computers to Chinese servers, raising national security concerns.

Apple’s revenue rises despite an 11% drop in China sales

Apple’s Q1 2025 revenue rose 4% to US$124.3B, despite an 11% decline in China iPhone sales. Strong growth in services and Mac sales helped offset losses.

Intel secures US$2.2 billion in federal grants for chip production

Intel secures US$2.2 billion in CHIPS Act grants to boost U.S. semiconductor manufacturing, with an additional US$5.66 billion pending disbursement.

Marvel Snap is set to return to app stores, confirms developer

Second Dinner, developer of Marvel Snap, says the company will begin its return to app stores after TikTok-linked outages, starting with Google Play.

Apple CEO praises DeepSeek’s AI despite controversy

Apple CEO Tim Cook praises DeepSeek’s AI despite OpenAI’s allegations, while Apple Intelligence faces a slow start and AI news summaries spark controversy.

Nvidia’s DLSS 4 brings enhanced image quality and efficiency

Nvidia’s latest GPU driver update brings DLSS 4 to unsupported games, improves video upscaling, and introduces Smooth Motion for RTX 50-series owners.

Apple’s revenue rises despite an 11% drop in China sales

Apple’s Q1 2025 revenue rose 4% to US$124.3B, despite an 11% decline in China iPhone sales. Strong growth in services and Mac sales helped offset losses.

Pentagon moves to block DeepSeek after staff access Chinese servers

The Pentagon is blocking DeepSeek after employees unknowingly connected work computers to Chinese servers, raising national security concerns.

Related Articles

Popular Categories