# Ghost Tapped: Chinese Tap-to-Pay Android Malware — NFC Relay Fraud at Scale

> Chinese cybercriminal groups are deploying Android malware targeting NFC tap-to-pay systems in a technique dubbed 'Ghost Tap' — enabling real-time relay of stolen payment card NFC data from attacker devices to money mules at point-of-sale (PoS) terminals worldwide. The attack chain begins with mobile banking malware (overlay attacks, keyloggers) or SMS phishing to steal credit card credentials and one-time passwords, enabling attackers to link stolen cards to Google Pay or Apple Pay on their devices. The stolen tap-to-pay tokenized card data is then relayed via NFCGate (a legitimate NFC research tool from TU Darmstadt, weaponized for fraud) to mule devices at retail PoS terminals — enabling fraudulent purchases at scale. The relay architecture allows the attacker with the stolen card to be in a different country from the mule making purchases. Multiple mules can use the same stolen card simultaneously across different locations within seconds. Related malware family NGate (discovered by ESET, targeting Czech banks since Nov 2023) pioneered NFC relay for ATM cash withdrawal; Ghost Tap evolves this into PoS-based retail fraud at massive scale. Key challenges: transactions appear to originate from the legitimate linked device (no new device signals), the attacker's device can be in airplane mode (no location data), amounts are kept below fraud thresholds, and impossible-travel detection is the primary defense. This represents the weaponization of contactless payment infrastructure — the same convenience that makes tap-to-pay fast makes it exploitable for real-time relay fraud.

- **Published:** 2026-02-12T05:12:00Z
- **Last reviewed:** 2026-02-12T05:12:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0067
- **ID:** TL-2026-0067
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Chinese cybercriminal groups (China)
- **Detections:** 9 · **IOCs:** 33 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Ghost Tapped: Chinese Tap-to-Pay Android Malware — NFC Relay Fraud at Scale

Sources: Group-IB ('Ghost Tapped: Tracking the Rise of Chinese Tap-to-pay Android Malware'), ThreatFabric ('Ghost Tap: New Cash-Out Tactic with NFC Relay'), ESET (NGate malware analysis), The Hacker News.

Attack Overview:

Ghost Tap is a cash-out technique that leverages NFC relay technology to enable remote, scalable, anonymous fraud using stolen credit card details linked to mobile payment services (Google Pay, Apple Pay, Samsung Pay). Chinese cybercriminal groups have adopted and scaled this technique, creating organized networks of mules and relay infrastructure.

=== PHASE 1: CREDENTIAL THEFT ===

Multiple vectors for initial card compromise:

1. Mobile Banking Malware: Android banking trojans with overlay attack capability. When victim opens legitimate banking app, malware displays a pixel-perfect fake login screen over the real app. Captures: card number, CVV, expiry, banking credentials. Keylogger component captures additional input including OTPs.

2. SMS Phishing (Smishing): Victim receives SMS impersonating bank, delivery service, or government agency. Link leads to phishing site that captures card details. Site requests OTP to 'verify identity' — actually used to link card to attacker's device.

3. Voice Phishing (Vishing): Attacker calls victim posing as bank employee, claims account is compromised. Instructs victim to install 'security app' (actually malware). Victim provides card PIN and enables NFC for 'verification' — malware captures NFC data.

4. Progressive Web Apps (PWAs) / WebAPKs: Malicious PWAs that mimic banking apps, distributed via phishing links. No Google Play Store involvement — sideloaded via browser. Difficult to distinguish from legitimate apps.

Credentials Captured: Card number, CVV, expiry date, cardholder name, banking PIN, OTP/2FA codes (intercepted from SMS or push notifications).

=== PHASE 2: CARD LINKING ===

With stolen card credentials + intercepted OTP:
1. Attacker enrolls stolen card into Google Pay or Apple Pay on their own device
2. Bank sends verification OTP to victim's phone → intercepted by malware → sent to attacker
3. Card successfully linked to attacker's mobile payment system
4. Attacker now has a tokenized tap-to-pay version of the victim's card

This is the critical bridge — converting stolen static credentials into a live, tokenized mobile payment capability.

=== PHASE 3: NFC RELAY (GHOST TAP) ===

Technology: NFCGate — originally developed by TU Darmstadt's Secure Mobile Networking Lab for NFC security research. Open-source, available on GitHub. Has been weaponized for fraud.

Architecture:
- ATTACKER device: Has stolen card linked to Google Pay/Apple Pay. Runs NFCGate in 'reader' mode. Can be in a different country. Can be in airplane mode.
- RELAY SERVER: Intermediary server that routes NFC traffic between attacker and mule in real-time. Low latency required for transaction timeout compliance.
- MULE device: Runs NFCGate in HCE (Host Card Emulation) mode. Physically present at PoS terminal. Taps phone on PoS reader — relayed NFC data from attacker's device is transmitted.

The PoS terminal communicates with the mule's phone, which relays all NFC communication to/from the attacker's phone in real-time. The PoS terminal 'sees' a valid Google Pay/Apple Pay transaction from the linked card.

=== PHASE 4: CASH-OUT ===

Mule Operations:
- Multiple mules at different retail locations simultaneously
- Purchase high-value, easily resellable items (gift cards preferred — anonymous, liquid)
- Keep individual transaction amounts below fraud detection thresholds
- Same stolen card used at multiple locations within seconds (impossible travel)
- Mules require no technical skill — just an Android phone with NFCGate and instructions

Scale Advantages:
- One attacker can service dozens of mules simultaneously
- Cards can be used across multiple countries in parallel
- No physical card or original phone needed at PoS
- Anonymous — mules are disposable, attacker is remote
- Gift cards converted to cash or cryptocurrency

=== RELATED: NGate MALWARE (ESET, Aug 2024) ===

NGate is the predecessor technique, documented by ESET targeting 3 Czech banks since November 2023:
- Malware prompts victim to enable NFC and hold physical card to phone
- NFC data from PHYSICAL card relayed to attacker's rooted Android device
- Attacker uses relayed NFC data to withdraw cash from ATMs
- 6 NGate app variants identified (Nov 2023 — Mar 2024)
- Campaign halted after 22-year-old arrested by Czech police
- Key difference: NGate relays victim's PHYSICAL card data for ATM withdrawal; Ghost Tap relays TOKENIZED card data from attacker's device for PoS purchases

=== DETECTION CHALLENGES ===

1. Transaction Legitimacy: PoS sees a valid Google Pay/Apple Pay transaction from the enrolled device. No red flags at the payment protocol level.

2. Single Device Appearance: All transactions appear from the same device (attacker's phone with linked card). No suspicious multi-device patterns.

3. Airplane Mode Evasion: Attacker's device can be in airplane mode, preventing location tracking. NFC relay works over the mule's network connection.

4. Below-Threshold Amounts: Individual purchases kept small. Aggregate fraud significant but distributed across locations.

5. No Malware at PoS: NFCGate on the mule device is not traditional malware — it's a legitimate research tool. No signatures exist.

6. Speed: NFC relay adds only milliseconds of latency. Modern 5G networks make cross-country relay virtually instantaneous.

=== DETECTION OPPORTUNITIES ===

1. Impossible Travel: Same card used at locations that are physically impossible to reach between transactions. This is the strongest detection signal.

2. New Device Enrollment: Card linked to new device, especially when combined with malware detected on victim's original device.

3. Transaction Velocity: Multiple PoS transactions across geographically dispersed locations within minutes.

4. Gift Card Purchase Patterns: High-value gift card purchases from newly enrolled cards.

5. NFC Timing Anomalies: Relay adds latency to NFC communication. PoS terminals could detect non-standard NFC response timing.

6. Device Location Inconsistency: If device location data is available, mismatch between device GPS and PoS terminal location indicates relay.

## MITRE ATT&CK

- T1566 Phishing
- T1195 Supply Chain Compromise
- T1204 User Execution
- T1037 Boot or Logon Initialization Scripts
- T1056 Input Capture
- T1111 Multi-Factor Authentication Interception
- T1539 Steal Web Session Cookie
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1090 Proxy
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft
- T1036 Masquerading
- T1685 Disable or Modify Tools
- T1082 System Information Discovery
- T1588 Obtain Capabilities
- T1587 Develop Capabilities
- T1546 Event Triggered Execution
- T1553 Subvert Trust Controls
- T1070 Indicator Removal
- T1556 Modify Authentication Process
- T1113 Screen Capture
- T1095 Non-Application Layer Protocol
- T1531 Account Access Removal
- T1585 Establish Accounts
- T1583 Acquire Infrastructure

## Sources

- [Group-IB — Ghost Tapped: Chinese Tap-to-Pay Android Malware](https://www.group-ib.com/blog/ghost-tapped/)
- [ThreatFabric — Ghost Tap: NFC Relay Cash-Out Tactic](https://www.threatfabric.com/blogs/ghost-tap-new-cash-out-tactic-with-nfc-relay)
- [The Hacker News — Ghost Tap: NFCGate Exploit](https://thehackernews.com/2024/11/ghost-tap-hackers-exploiting-nfcgate-to.html)
- [ESET — NGate Android NFC Malware](https://www.welivesecurity.com/en/eset-research/ngate-android-malware-relays-nfc-traffic-to-steal-cash/)
- [The Hacker News — NGate NFC Card Cloning](https://thehackernews.com/2024/08/new-android-malware-ngate-steals-nfc.html)
- [NFCGate GitHub (TU Darmstadt)](https://github.com/nfcgate/nfcgate)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0067
