Tuesday, 14 October 2025
27.4 C
Singapore
26 C
Thailand
20.2 C
Indonesia
27.9 C
Philippines

ESET unveils NGate: Android malware used in Czech ATM fraud

Discover how NGate, a new Android malware, relays NFC data to clone ATM cards and facilitate unauthorised withdrawals, as uncovered by ESET Research.

ESET Research has identified a novel form of Android malware known as NGate, which has been utilised to carry out sophisticated attacks on customers of three Czech banks. This malware uniquely captures and relays NFC traffic, enabling attackers to withdraw cash from ATMs by cloning the data from victims’ payment cards.

Detailed operation of NGate

NGate infiltrates Android devices through a malicious app that deceives users into believing they are responding to legitimate security concerns from their bank. Once installed, it enables criminals to capture NFC data from the victim’s payment card and transmit it to an attacker-controlled device. This setup allows the replication of the victim’s card, facilitating cash withdrawals from ATMs without the need for physical access to the card or rooting the victim’s device.

Lukáš Štefanko of ESET elucidated the operation, saying, “We haven’t seen this novel NFC relay technique in any previously discovered Android malware. The technique is based on a tool called NFCGate, designed by students at the Technical University of Darmstadt, Germany, to capture, analyse, or alter NFC traffic; therefore, we named this new malware family NGate.”

Victims were duped into installing NGate via deceptive SMS messages that falsely alerted them about a compromised device due to a tax issue and urged them to install a linked application. Crucially, NGate was never available on the official Google Play store.

Prevention and implications

The malware campaign began in November 2023 and involved domains impersonating legitimate banking platforms. It was part of a broader phishing strategy that included using progressive web apps and WebAPKs to distribute malicious content. By March 2024, following the arrest of a suspect linked to these activities, the spread of NGate had been curtailed.

ESET Research advises the public to adopt proactive security measures to mitigate the risk of such advanced threats. Ensuring security involves checking website URLs, downloading apps only from trusted sources, keeping PIN codes secret, using security apps on smartphones, turning off NFC when not in use, employing protective cases, and opting for virtual cards that require authentication.

Hot this week

Armis and Fortinet expand partnership to boost cyber resilience for global businesses

Armis and Fortinet have expanded their partnership to enhance cyber resilience with deeper integration, unified visibility, and automated security enforcement.

Anthropic study reveals malicious data can easily sabotage AI models

Anthropic warns that small amounts of malicious training data can easily sabotage large AI models like Claude.

Google offers free AI Pro plan to students in Singapore

Google is offering students in Singapore a free one-year subscription to its AI Pro plan, featuring Gemini 2.5 Pro and powerful learning tools.

Google offers Singapore students free one-year access to the AI Pro Plan

Singapore students can apply for a free one-year Google AI Pro Plan subscription powered by Gemini 2.5 Pro.

GovWare 2025 to spotlight the future of cybersecurity and digital trust

GovWare 2025 will gather over 13,000 cybersecurity leaders in Singapore from 21 to 23 October to shape the future of digital trust.

Salesforce enhances Agentforce to tackle cyber threats and automate compliance

Salesforce enhances Agentforce with new tools to combat cyber threats and automate compliance, strengthening security and simplifying data protection.

Square Enix unveils new Dissidia Final Fantasy after eight years, but fans are disappointed by mobile exclusivity

Square Enix announces a new Dissidia Final Fantasy for mobile, but fans express disappointment after eight years without a mainline release.

Samsung Galaxy XR headset details revealed ahead of expected launch

Samsung’s Galaxy XR headset leak reveals dual 4K displays, Snapdragon XR2+ Gen 2 chip, and a rumoured 22 October launch.

Belkin unveils Stage PowerGrip: a magnetic iPhone accessory with built-in power bank

Belkin unveils the Stage PowerGrip, a magnetic iPhone grip that doubles as a multi-device charger with a 9,300mAh battery.

Related Articles