Threat reportMalwareTL-2026-0067
Ghost Tapped: Chinese Tap-to-Pay Android Malware — NFC Relay Fraud at Scale
Ghost Tapped (TL-2026-0067) is a high-severity malware campaign, first published 2026-02-12. It is attributed to Chinese cybercriminal groups (China) with medium confidence, maps to 26 MITRE ATT&CK techniques (T1005, T1036, T1037), and is covered by 9 detection rules and 33 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 26MITRE ATT&CK
- Actors
- 1Chinese cybercriminal groups
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 33Indicators of compromise
Key facts for TL-2026-0067
- Threat ID
- TL-2026-0067
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Chinese cybercriminal groups
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- Financial Services, Retail, Banking, Mobile Payment Platforms, Consumer
- Target regions
- Global — any region with NFC/contactless payment infrastructure. Initial NGate activity in Czechia. Ghost Tap promoted on Chinese-language underground forums. Cash-out operations span multiple countries simultaneously.
- Detection rules
- 9
- Indicators of compromise
- 33
Malware and tooling in Ghost Tapped
Malware and tooling: NFSkate — Android malware family using NFCGate for NFC relay, documented by ThreatFabric Apr 2024, NFSkate — NFCGate-based Android malware bridging NGate and Ghost Tap (ThreatFabric), NGate — 6 Android malware variants targeting Czech banks via NFC relay for ATM withdrawal (ESET), NGate — Android malware family (6 variants) targeting Czech banks via NFC relay for ATM withdrawal, NFCGate (de.tu_darmstadt.seemoo.nfcgate) — legitimate NFC tool weaponized for relay fraud, NFCGate (github.com/nfcgate/nfcgate) — legitimate NFC research tool weaponized for payment relay fraud, NFCGate app installed on non-researcher Android device — used for NFC relay between attacker and mule devices
How Ghost Tapped works
Chinese cybercriminal groups are deploying Android malware targeting NFC tap-to-pay systems in a technique dubbed 'Ghost Tap' — enabling real-time relay of stolen payment card NFC data from attacker devices to money mules at point-of-sale (PoS) terminals worldwide. The attack chain begins with mobile banking malware (overlay attacks, keyloggers) or SMS phishing to steal credit card credentials and one-time passwords, enabling attackers to link stolen cards to Google Pay or Apple Pay on their devices. The stolen tap-to-pay tokenized card data is then relayed via NFCGate (a legitimate NFC research tool from TU Darmstadt, weaponized for fraud) to mule devices at retail PoS terminals — enabling fraudulent purchases at scale. The relay architecture allows the attacker with the stolen card to be in a different country from the mule making purchases. Multiple mules can use the same stolen card simultaneously across different locations within seconds. Related malware family NGate (discovered by ESET, targeting Czech banks since Nov 2023) pioneered NFC relay for ATM cash withdrawal; Ghost Tap evolves this into PoS-based retail fraud at massive scale. Key challenges: transactions appear to originate from the legitimate linked device (no new device signals), the attacker's device can be in airplane mode (no location data), amounts are kept below fraud thresholds, and impossible-travel detection is the primary defense. This represents the weaponization of contactless payment infrastructure — the same convenience that makes tap-to-pay fast makes it exploitable for real-time relay fraud.
Ghost Tapped: Chinese Tap-to-Pay Android Malware — NFC Relay Fraud at Scale
Sources: Group-IB ('Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android Malware'), ThreatFabric ('Ghost Tap: New Cash-Out Tactic with NFC Relay'), ESET (NGate malware analysis), The Hacker News.
Attack Overview:
Ghost Tap is a cash-out technique that leverages NFC relay technology to enable remote, scalable, anonymous fraud using stolen credit card details linked to mobile payment services (Google Pay, Apple Pay, Samsung Pay). Chinese cybercriminal groups have adopted and scaled this technique, creating organized networks of mules and relay infrastructure.
=== PHASE 1: CREDENTIAL THEFT ===
Multiple vectors for initial card compromise:
1. Mobile Banking Malware: Android banking trojans with overlay attack capability. When victim opens legitimate banking app, malware displays a pixel-perfect fake login screen over the real app. Captures: card number, CVV, expiry, banking credentials. Keylogger component captures additional input including OTPs.
2. SMS Phishing (Smishing): Victim receives SMS impersonating bank, delivery service, or government agency. Link leads to phishing site that captures card details. Site requests OTP to 'verify identity' — actually used to link card to attacker's device.
3. Voice Phishing (Vishing): Attacker calls victim posing as bank employee, claims account is compromised. Instructs victim to install 'security app' (actually malware). Victim provides card PIN and enables NFC for 'verification' — malware captures NFC data.
4. Progressive Web Apps (PWAs) / WebAPKs: Malicious PWAs that mimic banking apps, distributed via phishing links. No Google Play Store involvement — sideloaded via browser. Difficult to distinguish from legitimate apps.
Credentials Captured: Card number, CVV, expiry date, cardholder name, banking PIN, OTP/2FA codes (intercepted from SMS or push notifications).
=== PHASE 2: CARD LINKING ===
With stolen card credentials + intercepted OTP: 1. Attacker enrolls stolen card into Google Pay or Apple Pay on their own device 2. Bank sends verification OTP to victim's phone → intercepted by malware → sent to attacker 3. Card successfully linked to attacker's mobile payment system 4. Attacker now has a tokenized tap-to-pay version of the victim's card
This is the critical bridge — converting stolen static credentials into a live, tokenized mobile payment capability.
=== PHASE 3: NFC RELAY (GHOST TAP) ===
Technology: NFCGate — originally developed by TU Darmstadt's Secure Mobile Networking Lab for NFC security research. Open-source, available on GitHub. Has been weaponized for fraud.
Architecture: - ATTACKER device: Has stolen card linked to Google Pay/Apple Pay. Runs NFCGate in 'reader' mode. Can be in a different country. Can be in airplane mode. - RELAY SERVER: Intermediary server that routes NFC traffic between attacker and mule in real-time. Low latency required for transaction timeout compliance. - MULE device: Runs NFCGate in HCE (Host Card Emulation) mode. Physically present at PoS terminal. Taps phone on PoS reader — relayed NFC data from attacker's device is transmitted.
The PoS terminal communicates with the mule's phone, which relays all NFC communication to/from the attacker's phone in real-time. The PoS terminal 'sees' a valid Google Pay/Apple Pay transaction from the linked card.
=== PHASE 4: CASH-OUT ===
Mule Operations: - Multiple mules at different retail locations simultaneously - Purchase high-value, easily resellable items (gift cards preferred — anonymous, liquid) - Keep individual transaction amounts below fraud detection thresholds - Same stolen card used at multiple locations within seconds (impossible travel) - Mules require no technical skill — just an Android phone with NFCGate and instructions
Scale Advantages: - One attacker can service dozens of mules simultaneously - Cards can be used across multiple countries in parallel - No physical card or original phone needed at PoS - Anonymous — mules are disposable, attacker is remote - Gift cards converted to cash or cryptocurrency
=== RELATED: NGate MALWARE (ESET, Aug 2024) ===
NGate is the predecessor technique, documented by ESET targeting 3 Czech banks since November 2023: - Malware prompts victim to enable NFC and hold physical card to phone - NFC data from PHYSICAL card relayed to attacker's rooted Android device - Attacker uses relayed NFC data to withdraw cash from ATMs - 6 NGate app variants identified (Nov 2023 — Mar 2024) - Campaign halted after 22-year-old arrested by Czech police - Key difference: NGate relays victim's PHYSICAL card data for ATM withdrawal; Ghost Tap relays TOKENIZED card data from attacker's device for PoS purchases
=== DETECTION CHALLENGES ===
1. Transaction Legitimacy: PoS sees a valid Google Pay/Apple Pay transaction from the enrolled device. No red flags at the payment protocol level.
2. Single Device Appearance: All transactions appear from the same device (attacker's phone with linked card). No suspicious multi-device patterns.
3. Airplane Mode Evasion: Attacker's device can be in airplane mode, preventing location tracking. NFC relay works over the mule's network connection.
4. Below-Threshold Amounts: Individual purchases kept small. Aggregate fraud significant but distributed across locations.
5. No Malware at PoS: NFCGate on the mule device is not traditional malware — it's a legitimate research tool. No signatures exist.
6. Speed: NFC relay adds only milliseconds of latency. Modern 5G networks make cross-country relay virtually instantaneous.
=== DETECTION OPPORTUNITIES ===
1. Impossible Travel: Same card used at locations that are physically impossible to reach between transactions. This is the strongest detection signal.
2. New Device Enrollment: Card linked to new device, especially when combined with malware detected on victim's original device.
3. Transaction Velocity: Multiple PoS transactions across geographically dispersed locations within minutes.
4. Gift Card Purchase Patterns: High-value gift card purchases from newly enrolled cards.
5. NFC Timing Anomalies: Relay adds latency to NFC communication. PoS terminals could detect non-standard NFC response timing.
6. Device Location Inconsistency: If device location data is available, mismatch between device GPS and PoS terminal location indicates relay.
MITRE ATT&CK techniques used in TL-2026-0067
collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture
defense-evasion
T1036 Masquerading; T1070 Indicator Removal
persistence
T1037 Boot or Logon Initialization Scripts
exfiltration
T1041 Exfiltration Over C2 Channel
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1095 Non-Application Layer Protocol
discovery
T1082 System Information Discovery
credential-access
T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1556 Modify Authentication Process
initial-access
T1195 Supply Chain Compromise; T1566 Phishing
execution
impact
T1531 Account Access Removal; T1657 Financial Theft
privilege-escalation
T1546 Event Triggered Execution
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
resource-development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities
Remediation for Ghost Tapped
Patches
- Google Play Protect: automatically blocks known NGate variants (does not prevent NFCGate installation as it's a legitimate tool)
- PoS terminal firmware: vendors should develop NFC relay detection based on communication timing analysis
- Android: no OS-level fix possible without breaking legitimate HCE/NFC functionality
Immediate actions
- Financial institutions: implement impossible-travel detection for contactless transactions — same card at geographically impossible locations within short timeframes
- Monitor for new device enrollments in Google Pay/Apple Pay, especially when paired with malware detection or credential compromise signals on the cardholder's original device
- Deploy transaction velocity monitoring: multiple PoS transactions from same tokenized card across dispersed locations within minutes
- Alert on high-value gift card purchases from newly enrolled mobile payment devices — preferred cash-out pattern for Ghost Tap mules
- Android users: only install banking apps from Google Play Store. Never sideload APKs from SMS links, even if they appear to be from your bank
Workarounds
- Disable NFC on Android devices when not actively making payments
- Set low contactless payment limits on cards — reduces per-transaction fraud amount
- Enable transaction notifications: immediate SMS/push alerts for every card transaction enable rapid fraud detection
- Use biometric authentication (fingerprint/face) for mobile payments — prevents relay if attacker's device is locked
- Monitor bank statements daily during periods of active Ghost Tap campaigns
Longer-term hardening
- PoS terminal manufacturers: implement NFC timing analysis — relay adds detectable latency to NFC communication. Transactions with non-standard timing profiles should be flagged
- Payment networks: develop device-location-to-PoS-location correlation — if device GPS does not match PoS terminal location, flag as potential relay
- Mobile payment providers: implement continuous device integrity checking — detect rooted/modified devices and NFCGate installation
- Banks: combine device risk signals with transaction monitoring — malware detected on customer device + new device enrollment + PoS transactions = high-confidence fraud chain
- Industry collaboration: share Ghost Tap fraud patterns across payment networks, banks, and PoS vendors for coordinated detection improvement
- Consumer education: awareness campaigns about vishing attacks impersonating banks, risks of installing apps from SMS links, and importance of not sharing OTPs
Weaknesses (CWE) in Ghost Tapped
Timeline of Ghost Tapped
- NFCGate developed by TU Darmstadt Secure Mobile Networking Lab for NFC security research. Open-source tool that can capture, analyze, modify NFC traffic and relay NFC data between two devices via a server. Legitimate research tool that would later be weaponized for fraud.
- NGate malware campaign begins targeting 3 Czech banks. Uses progressive web apps (PWAs) and WebAPKs to phish banking credentials. Instructs victims to enable NFC and hold physical payment card to phone, relaying NFC data to attacker's rooted device for ATM withdrawals. 6 NGate app variants deployed. Source: ESET.
- Czech police arrest 22-year-old connected to NGate ATM fraud. Campaign activity ceases after arrest. Demonstrates law enforcement capability to track NFC relay fraud — but only in the physical-card-to-ATM variant. Source: Czech Police.
- ThreatFabric reports NFSkate malware family (private report) using NFCGate for NFC relay. NFSkate is the evolutionary link between NGate (physical card relay) and Ghost Tap (tokenized card relay). Source: ThreatFabric.
- ESET publishes comprehensive analysis of NGate malware. Documents the full attack chain: SMS phishing → PWA/WebAPK → credential theft → NFC relay to attacker device → ATM cash withdrawal. Identifies NFCGate as the underlying relay technology. 6 app variants documented. Source: ESET WeLiveSecurity.
- ThreatFabric publishes 'Ghost Tap: New Cash-Out Tactic with NFC Relay.' Documents evolution from physical card relay (NGate) to tokenized mobile payment relay. Attackers link stolen cards to Google Pay/Apple Pay, then relay NFC data to mules at PoS terminals. Underground forum posts advertising the technique. Source: ThreatFabric.
- Group-IB publishes 'Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android Malware.' Documents Chinese cybercriminal adoption and scaling of Ghost Tap technique. Organized mule networks, relay infrastructure, and systematic targeting of NFC payment systems. Chinese-language underground forums promoting the technique. Source: Group-IB.
- Threadlinqs analysis: Ghost Tap represents the weaponization of contactless payment convenience. The same properties that make tap-to-pay fast (no PIN for small amounts, NFC tokenization, instant processing) make it exploitable for relay fraud. Detection must shift from transaction-level analysis to behavioral-level analysis: impossible travel, transaction velocity, device-location mismatch, and gift card purchase patterns. PoS terminals need NFC timing analysis — relay adds detectable latency. The fundamental challenge: NFC relay is a protocol-level attack that the payment infrastructure was not designed to detect.
- As of 2026-05-29, Ghost Tap NFC-relay fraud remains ACTIVE and expanding: no CVE/patch applies (NFCGate is a legit tool), and Group-IB, Kaspersky (2026, 80+ samples), Cleafy and Recorded Future document a thriving Chinese MaaS ecosystem (SuperCard X, RatOn, NGate). Arrests (Czech 2024, Russia Dec 2025) and Huione's May-2025 shutdown caused only migration, not disruption; ESET found a new AI-assisted NGate variant hitting Brazil in April 2026.
Sources cited for Ghost Tapped
Detection coverage for TL-2026-0067
As of 2026-02-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0067 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.