NGate Android Malware — HandyPay-Trojanized NFC Relay Variant Targets Brazilian Cardholders via Fake Rio de Prêmios Lottery and Counterfeit Google Play Lures
NGate Android Malware (TL-2026-0401), also tracked as NGate HandyPay variant, is a high-severity malware campaign, first published 2026-04-21. It has no confirmed attribution, affects Google Android, maps to 11 MITRE ATT&CK techniques (T1406, T1409, T1417), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-0401
- Threat ID
- TL-2026-0401
- Also known as
- NGate HandyPay variant, NGate Brazil 2026, Proteção Cartão malware, Rio de Prêmios malware, Android/Spy.NGate.CC, Android/Spy.NGate.CB
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-04-21
- Last reviewed
- 2026-04-21
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- banking, financial-services, retail-payments, consumer
- Target regions
- Brazil, South America, LATAM
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in NGate Android Malware
Malware and tooling: Android/Spy.NGate.CB, Android/Spy.NGate.CC, NGate, HandyPay (trojanized)
ESET Research disclosed on 2026-04-21 a new NGate Android malware variant that abandons the open-source NFCGate relay tool and instead trojanizes the legitimate HandyPay NFC payment app. Active since 2025-11-08, the campaign targets Brazilian cardholders through a fake Rio de Prêmios lottery scratch-card website and a counterfeit Google Play page for a bogus 'Proteção Cartão' app, with WhatsApp used as a pivot to deliver APKs. Once installed, the app phishes the card PIN, relays the victim's tapped EMV contactless data to an attacker-paired Android device via HandyPay's own email-linked relay, and exfiltrates the PIN separately over HTTP to a C&C that doubles as the APK distribution server, enabling ATM cashouts and fraudulent contactless purchases against at least four confirmed Brazilian victims.
How NGate Android Malware works
On 2026-04-21, ESET researcher Lukas Stefanko disclosed a new evolution of the NGate Android malware family that departs from prior tradecraft by trojanizing the legitimate HandyPay NFC payment app instead of wrapping the open-source NFCGate tool (original 2024 Czech campaign) or paying for Malware-as-a-Service NFC relay kits such as NFU Pay or TX-NFC (used by the October 2025 PhantomCard Brazil campaign). HandyPay, available on Google Play since 2021, is a legitimate app that relays NFC payment-card data between two email-paired devices; its design requires zero Android permissions beyond default-payment-app designation, which makes it ideal cover for stealthy abuse. The unmodified HandyPay has never been available as the trojanized build on Google Play.
The operation is distributed through two lures hosted on the same server, implying a single threat actor. The first is a fake 'Rio de Prêmios' scratch-card site impersonating the legitimate Loterj-operated Rio de Janeiro state lottery; the scratch game is rigged so the victim always 'wins' R$20,000 and the 'Resgatar meu prêmio agora' button opens WhatsApp with a prefilled message to a fraudulent account whose profile image impersonates Caixa Econômica Federal — Brazil's federal bank that administers most Brazilian lotteries. Victims are then instructed to download the patched HandyPay APK as 'Rio_de_Prêmios_Pagamento.apk'. The second lure is a counterfeit Google Play product page advertising 'Proteção Cartão' (Card Protection) which delivers 'PROTECAO_CARTAO.apk' — similar naming to the October 2025 PhantomCard campaign, suggesting operator overlap or a shared playbook.
Technical execution: after the victim sideloads the APK (bypassing Android 'unknown sources' warnings), the trojanized HandyPay requests to become the default NFC payment handler — ESET confirms this is social-engineering theater because only the attacker's paired device actually needs that designation for the relay to succeed. The patched UI injects a PIN-entry box (MITRE T1417.002 GUI Input Capture) and instructs the victim to tap their contactless payment card against the phone. The legitimate HandyPay NFC-reader routine captures the EMV APDU exchange and relays it via HandyPay's own infrastructure to an attacker-operated Android device that is pre-paired via one of two hardcoded attacker email addresses observed across samples; that device can then emulate the victim's card at any NFC-capable ATM or POS terminal. Separately, the malicious patch issues an HTTP POST of the captured PIN to a dedicated C&C at 108.165.230.223, independent of HandyPay infrastructure. This same C&C server also hosts the malicious APKs and the fake Rio de Prêmios + Google Play pages, centralizing delivery and collection.
ESET's C&C analysis recovered logs from four compromised devices, all geolocated in Brazil, containing captured PINs, victim IPs, and timestamps. ESET assesses the malicious code was most probably produced with the assistance of a generative-AI / LLM, citing emoji characters left in debug log strings inside the PIN-exfiltration routine — a fingerprint typical of AI-generated text. This fits ESET's broader PromptSpy thesis that GenAI is lowering the barrier to entry for mobile-banking malware development. BleepingComputer corroborates the AI-assistance finding.
The C&C IP 108.165.230.223 is hosted by 'KAUA REIS DA SILVA trading as BattleHost' — a named Brazilian sole-trader hosting provider — providing a strong infrastructure-attribution pivot for further hunting. The distribution IP 104.21.91.170 sits on Cloudflare with the domain protecaocartao.online. Three ESET-flagged APK SHA-1 hashes (48A0DE6A43FC6E49318AD6873EA63FE325200DBC, A4F793539480677241EF312150E9C02E324C0AA2, 94AF94CA818697E1D99123F69965B11EAD9F010C) identify the Proteção Cartão and Rio de Prêmios builds; ESET detections are Android/Spy.NGate.CC and Android/Spy.NGate.CB. ESET notified the Google App Defense Alliance and HandyPay's developer, both of whom responded (Google added Play Protect detections; HandyPay opened an internal investigation). The NGate family now spans three geographic and technical phases: original NGate (Czechia, 2023-11 to 2024-03, NFCGate-based, culminated in a Prague arrest of a 22-year-old courier carrying 160,000 CZK), PhantomCard (Brazil, 2025-10, NFU Pay MaaS), and this HandyPay-trojanized variant (Brazil, 2025-11 to present).
MITRE ATT&CK techniques used in TL-2026-0401
defense-evasion
T1406 Obfuscated Files or Information; T1655 Masquerading
Collection
collection
Discovery
command-and-control
T1437 Application Layer Protocol
initial-access
T1476 Deliver Malicious App via Other Means; T1660 Phishing
Execution
Impact
Exfiltration
Affected products and versions in NGate Android Malware
- Google — Android
Vulnerable versions: 4.4+ (any Android with HCE/NFC payment support) - HandyPay (impersonated / trojanized) — HandyPay NFC Relay App for Android
Vulnerable versions: trojanized repackage (not the Google Play build)
Fixed in: official HandyPay on Google Play is unaffected - EMVCo (payment scheme) — Contactless EMV payment cards (Visa, Mastercard, Elo, Hipercard)
Vulnerable versions: any contactless-capable EMV card tapped on a compromised device
Fixed in: tokenized cards in Google Wallet / Apple Wallet resist relay
Remediation for NGate Android Malware
Patches
- No software patch applicable — this is a trojanized-app social-engineering campaign, not a CVE-style vulnerability
- Ensure Google Play Protect is enabled and up-to-date; ESET-supplied detections for Android/Spy.NGate.CC and Android/Spy.NGate.CB are active as of 2026-04-21
Immediate actions
- Block domain protecaocartao.online at DNS and web proxy tiers
- Block outbound traffic to 104.21.91.170 and 108.165.230.223 at perimeter firewalls
- Alert on any Android device attempting to install APKs with SHA-1 hashes 48A0DE6A43FC6E49318AD6873EA63FE325200DBC, A4F793539480677241EF312150E9C02E324C0AA2, or 94AF94CA818697E1D99123F69965B11EAD9F010C
- Hunt for HTTP POSTs from Android user agents to 108.165.230.223 containing short numeric payloads consistent with 4- to 6-digit PIN exfiltration
- Push mobile-device-management policy disabling installation from unknown sources on managed Android fleets
- Communicate to Brazilian customer base: reject any WhatsApp lottery-prize messages from self-declared Caixa Econômica Federal accounts; never install APKs outside Google Play
Workarounds
- Disable Android NFC when not actively making contactless payments
- Do not set any sideloaded app as the default NFC payment handler
- Enforce app installation restricted to Google Play via MDM on corporate Android devices
- For consumer banking apps targeting Brazil, add in-app warnings about lottery/prize lures using WhatsApp
Longer-term hardening
- Deploy managed mobile threat defense (MTD) with behavioral analytics — ESET Mobile Security, Lookout, or equivalent — on all employee and customer-facing Android devices
- Educate cardholders to prefer tokenized contactless payment via Google Wallet and Apple Wallet; both require per-transaction verification and defeat NFC relay
- Encourage RFID-blocking wallets and disabling NFC when not actively transacting
- Integrate ESET App Defense Alliance feed into Google Play Protect enterprise policies
- Subscribe to ESET and BleepingComputer advisories on NGate family to track future variants and MaaS expansion (NFU Pay, TX-NFC)
- Rotate card PINs for any customer observed installing sideloaded NFC-related apps
Weaknesses (CWE) in NGate Android Malware
CWE-506, CWE-1357
Timeline of NGate Android Malware
- Legitimate HandyPay NFC relay app first published on Google Play by its original developer.
- Original NGate malware variant first observed in the wild in Czechia, wrapping the open-source NFCGate tool to relay NFC data from Czech banking cardholders.
- Czech police arrest a 22-year-old NGate courier in Prague carrying approximately 160,000 CZK (about USD 6,500) in cash withdrawn via relayed NFC ATM transactions.
- ESET (Lukas Stefanko and Jakub Osmani) publishes the original NGate research naming the family and documenting the NFCGate-based Czech campaign.
- PhantomCard NGate variant targets Brazilian cardholders using fake card-protection app names and the NFU Pay MaaS offering — establishing the lineage and playbook for the 2025-11 HandyPay variant.
- Distribution domain protecaocartao.online and IP 104.21.91.170 (Cloudflare) first observed — effective start of the HandyPay-variant campaign.
- C&C IP 108.165.230.223 first observed, hosted by KAUA REIS DA SILVA trading as BattleHost (Brazil).
- ESET WeLiveSecurity publishes full disclosure of the HandyPay-trojanized NGate variant; BleepingComputer covers the same day; ESET notifies Google App Defense Alliance (Play Protect detections added) and HandyPay's developer (internal investigation confirmed); C&C logs show four Brazilian victims already compromised.
- As of 2026-05-29, this NGate HandyPay NFC-relay campaign remains ACTIVE: ESET's 2026-04-21 disclosure reported it ongoing since Nov 2025 with "no signs of stopping," C&C/distribution infra still live, and no takedown, arrest, or sinkhole. No CVE applies (social-engineering trojan); the unattributed operator is at large amid rising Brazil NFC fraud.
Sources cited for NGate Android Malware
- ESET Research — New NGate variant hides in a trojanized NFC payment app
- BleepingComputer — NGate Android malware uses HandyPay NFC app to steal card data
- ESET Research — NGate Android malware relays NFC traffic to steal cash (original 2024 Czech campaign, family lineage)
- ESET GitHub — Indicators of Compromise repository
- MITRE ATT&CK for Mobile — T1660 Phishing
- MITRE ATT&CK for Mobile — T1417.002 Input Capture: GUI Input Capture
- MITRE ATT&CK for Mobile — T1646 Exfiltration Over C2 Channel
Threats related to NGate Android Malware
- NGate Android NFC Relay Malware Variant - Trojanized HandyPay Banking App Campaign Targeting Brazil (2025-2026)
- OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and Crypto Apps (Cyble CRIL)
- PromptSpy — First Android Malware Using Generative AI (Gemini) for Context-Aware UI Manipulation, VNC Remote Access, Chase Bank Impersonation
Detection coverage for TL-2026-0401
As of 2026-04-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0401 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.