Ghost Tapped: Chinese Tap-to-Pay Android Malware — NFC Relay Fraud at Scale — Threadlinqs Intelligence
As of 2026-05-30, Ghost Tapped: Chinese Tap-to-Pay Android Malware — NFC Relay Fraud at Scale is a high-severity malware threat attributed to Chinese cybercriminal groups (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-0067 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Chinese cybercriminal groups · China · FINANCIAL
Chinese cybercriminal groups are deploying Android malware targeting NFC tap-to-pay systems in a technique dubbed 'Ghost Tap' — enabling real-time relay of stolen payment card NFC data from attacker
Ghost Tapped: Chinese Tap-to-Pay Android Malware — NFC Relay Fraud at Scale
Sources: Group-IB ('Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android Malware'), ThreatFabric ('Ghost Tap: New Cash-Out Tactic with NFC Relay'), ESET (NGate malware analysis), The Hacker News.
Attack Overview:
Ghost Tap is a cash-out technique that leverages NFC relay technology to enable remote, scalable, anonymous fraud using stolen credit card details linked to mobile payment services (Google Pay, Apple Pay, Samsung Pay). Chinese cybercriminal groups have adopted and scaled this technique, creating organized networks of mules and relay infrastructure.
=== PHASE 1: CREDENTIAL THEFT ===
Multiple vectors for initial card compromise:
1. Mobile Banking Malware: Android banking trojans with overlay attack capability. When victim opens legitimate banking app, malware displays a pixel-perfect fake login screen over the real app. Captures: card number, CVV, expiry, banking credentials. Keylogger component captures additional input including OTPs.
2. SMS Phishing (Smishing): Victim receives SMS impersonating bank, delivery service, or government agency. Link leads to phishing site that captures card details. Site requests OTP to 'verify identity' — actually used to link card to attacker's device.
3. Voice Phishing (Vishing): Attacker calls victim posing as bank employee, claims account is compromised. Instructs victim to install 'security app' (actually malware). Victim provides card PIN and enables NFC for 'verification' — malware captures NFC data.
4. Progressive Web Apps (PWAs) / WebAPKs: Malicious PWAs that mimic banking apps, distributed via phishing links. No Google Play Store involvement — sideloaded via browser. Difficult to distinguish from legitimate apps.
Credentials Captured: Card number, CVV, expiry date, cardholder name, banking PIN, OTP/2FA codes (intercepted from SMS or push notifications).
=== PHASE 2: CARD LINKING ===
With stolen card credentials + intercepted OTP:
1. Attacker enrolls stolen card into Google Pay or Apple Pay on their own device
2. Bank sends verification OTP to victim's phone → intercepted by malware → sent to attacker
3. Card successfully linked to attacker's mobile payment system
4. Attacker now has a tokenized tap-to-pay version of the victim's card
This is the critical bridge — converting stolen static credentials into a live, tokenized mobile payment capability.
=== PHASE 3: NFC RELAY (GHOST TAP) ===
Technology: NFCGate — originally developed by TU Darmstadt's Secure Mobile Networking Lab for NFC security research. Open-source, available on GitHub. Has been weaponized for fraud.
Architecture:
- ATTACKER device: Has stolen card linked to Google Pay/Apple Pay. Runs NFCGate in 'reader' mode. Can be in a different country. Can be in airplane mode.
- RELAY SERVER: Intermediary server that routes NFC traffic between attacker and mule in real-time. Low latency required for transaction timeout compliance.
- MULE device: Runs NFCGate in HCE (Host Card Emulation) mode. Physically present at PoS terminal. Taps phone on PoS reader — relayed NFC data from attacker's device is transmitted.
The PoS terminal communicates with the mule's phone, which relays all NFC communication to/from the attacker's phone in real-time. The PoS terminal 'sees' a valid Google Pay/Apple Pay transaction from the linked card.
=== PHASE 4: CASH-OUT ===
Mule Operations:
- Multiple mules at different retail locations simultaneously
- Purchase high-value, easily resellable items (gift cards preferred — anonymous, liquid)
- Keep individual transaction amounts below fraud detection thresholds
- Same stolen card used at multiple locations within seconds (impossible travel)
- Mules require no technical skill — just an Android phone with NFCGate and instructions
Scale Advantages:
- One attacker can service dozens of mules simultaneously
- Cards can be used across multiple countries in parallel
- No physical card or original phone nee
Weaknesses (CWE)
CWE-345, CWE-290, CWE-300, CWE-294, CWE-287
Target sectors: Financial Services, Retail, Banking, Mobile Payment Platforms, Consumer
Target regions: Global — any region with NFC/contactless payment infrastructure. Initial NGate activity in Czechia. Ghost Tap promoted on Chinese-language underground forums. Cash-out operations span multiple countries simultaneously.
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1195, T1204, T1037, T1056, T1056, T1111, T1539, T1056, T1005