Friday, 29 August 2025
31.4 C
Singapore
33.4 C
Thailand
20.4 C
Indonesia
28.5 C
Philippines

ESET unveils NGate: Android malware used in Czech ATM fraud

Discover how NGate, a new Android malware, relays NFC data to clone ATM cards and facilitate unauthorised withdrawals, as uncovered by ESET Research.

ESET Research has identified a novel form of Android malware known as NGate, which has been utilised to carry out sophisticated attacks on customers of three Czech banks. This malware uniquely captures and relays NFC traffic, enabling attackers to withdraw cash from ATMs by cloning the data from victims’ payment cards.

Detailed operation of NGate

NGate infiltrates Android devices through a malicious app that deceives users into believing they are responding to legitimate security concerns from their bank. Once installed, it enables criminals to capture NFC data from the victim’s payment card and transmit it to an attacker-controlled device. This setup allows the replication of the victim’s card, facilitating cash withdrawals from ATMs without the need for physical access to the card or rooting the victim’s device.

Lukáš Å tefanko of ESET elucidated the operation, saying, “We haven’t seen this novel NFC relay technique in any previously discovered Android malware. The technique is based on a tool called NFCGate, designed by students at the Technical University of Darmstadt, Germany, to capture, analyse, or alter NFC traffic; therefore, we named this new malware family NGate.”

Victims were duped into installing NGate via deceptive SMS messages that falsely alerted them about a compromised device due to a tax issue and urged them to install a linked application. Crucially, NGate was never available on the official Google Play store.

Prevention and implications

The malware campaign began in November 2023 and involved domains impersonating legitimate banking platforms. It was part of a broader phishing strategy that included using progressive web apps and WebAPKs to distribute malicious content. By March 2024, following the arrest of a suspect linked to these activities, the spread of NGate had been curtailed.

ESET Research advises the public to adopt proactive security measures to mitigate the risk of such advanced threats. Ensuring security involves checking website URLs, downloading apps only from trusted sources, keeping PIN codes secret, using security apps on smartphones, turning off NFC when not in use, employing protective cases, and opting for virtual cards that require authentication.

Hot this week

Bangkok Bank expands partnership with New Relic to boost mobile banking reliability

Bangkok Bank expands its New Relic partnership to enhance mobile banking reliability, achieving 90% uptime gains and faster recovery.

Bus Aunty review: Bringing bus arrival times into the home

Bus Aunty brings real-time bus arrival times into Singapore homes with an e-ink display, but quirks and pricing limit its appeal.

Confluent launches streaming agents to accelerate real-time agentic AI

Confluent has launched Streaming Agents, enabling enterprises to scale real-time AI agents with secure integrations and contextual data.

Most Singapore retailers adopt AI but trust remains low

Nearly all Singapore retailers are adopting AI, but only 10% trust it to work independently, monday.com research finds.

xAI makes Grok 2.5 open source as Grok 3 release nears

xAI makes its Grok 2.5 AI model open source on Hugging Face, with Elon Musk confirming Grok 3 will follow in six months.

ChatGPT could be influencing the way people speak

A study suggests ChatGPT and similar AI tools are influencing spoken language, with AI buzzwords increasingly appearing in daily conversations.

Thinking Machines partners with OpenAI to accelerate AI adoption in Asia Pacific

Thinking Machines partners with OpenAI to expand enterprise AI adoption across Asia Pacific with training, app design, and leadership programmes.

100 women in tech power Singapore’s digital future as nation marks 60 years

Singapore honours 100 women leaders and 25 young achievers in the SG100WIT 2025 list, marking growing female impact in tech.

Synology introduces AI-powered Office Suite with new AI Console

Synology updates its Office Suite with AI-powered MailPlus, Office, and a new AI Console to boost productivity while ensuring data privacy.

Related Articles

Popular Categories