NGate Android NFC Relay Malware Variant - Trojanized HandyPay Banking App Campaign Targeting Brazil (2025-2026)

NGate Android NFC Relay Malware Variant (TL-2026-0407), also tracked as Android/Spy.NGate.CB, is a high-severity malware campaign, first published 2026-04-22. It is attributed to NGate Operator with low confidence, affects HandyPay HandyPay Android App (trojanized copies only), maps to 14 MITRE ATT&CK techniques (T1406, T1409, T1417), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-0407

Threat ID
TL-2026-0407
Also known as
Android/Spy.NGate.CB, Android/Spy.NGate.CC, Trojanized HandyPay, Protecao Cartao NGate, Rio de Premios NGate
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-04-22
Last reviewed
2026-04-22
Attribution
NGate Operator
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial, retail, consumer, banking
Target regions
Brazil, South America, Latin America
Detection rules
9
Indicators of compromise
26

Malware and tooling in NGate Android NFC Relay Malware Variant

Malware and tooling: Android/Spy.NGate.CB, Android/Spy.NGate.CC, NGate, HandyPay

ESET Research disclosed a new NGate Android malware variant that trojanizes the legitimate HandyPay NFC relay app to steal payment card data and PINs from Brazilian users. Distributed via a fake Rio de Premios lottery website and a fake Google Play page for a bogus Protecao Cartao (Card Protection) app, the malware forwards victims' NFC card data to an attacker-controlled device for contactless ATM cash-outs while exfiltrating captured PINs over HTTP. ESET assesses portions of the malicious code as AI-generated.

How NGate Android NFC Relay Malware Variant works

OVERVIEW

ESET Research disclosed on 2026-04-21 a fresh variant of the NGate Android malware family that abandons the previously-used open-source NFCGate tooling in favour of trojanizing a legitimate Android app called HandyPay. HandyPay has been on Google Play since 2021 and provides a legitimate NFC relay capability intended for sharing payment cards between paired family members or devices. The threat actor weaponised HandyPay's native functionality by injecting malicious code into the APK, distributing the trojanized package outside Google Play under two lures, and routing all captured NFC traffic to an attacker-controlled receiver device. The campaign has been active since 2025-11 and targets Android users in Brazil; ESET identified logs from four compromised Brazilian devices on the attacker C&C server containing captured PIN codes, IP addresses and timestamps.

DISTRIBUTION AND INITIAL ACCESS

Two trojanized samples were observed in the wild, both hosted on the same infrastructure (protecaocartao.online, fronted by Cloudflare at 104.21.91.170, with C&C at 108.165.230.223 hosted by BattleHost). The first lure is a phishing website that impersonates Rio de Premios, a scratch-card lottery run by Loterj (Rio de Janeiro state lottery operator). The rigged scratch card always reveals three matching symbols awarding the victim R$20,000. Claiming the prize opens WhatsApp with a prefilled message to a number whose profile impersonates Caixa Economica Federal, the Brazilian government-owned bank that manages most state lotteries. The victim is then directed to install a patched HandyPay APK renamed Rio_de_Premios_Pagamento.apk (SHA-1 94AF94CA818697E1D99123F69965B11EAD9F010C). The second lure is a fake Google Play web page for an app called Protecao Cartao (Portuguese: Card Protection), which delivers PROTECAO_CARTAO.apk (SHA-1 48A0DE6A43FC6E49318AD6873EA63FE325200DBC or A4F793539480677241EF312150E9C02E324C0AA2). Android's install prompt blocks the sideload until the victim enables installation from unknown sources.

EXECUTION AND FUNCTIONALITY

Once installed, the app requests to be set as the device's default payment application - a legitimate HandyPay prompt that is retained unchanged. Crucially, no additional Android permissions are requested, which keeps the malware's detection surface extremely small. The operator's paired device (linked to an attacker email hardcoded in the APK; two distinct operator email addresses were observed across samples) performs the receiving side of the relay, which requires default-payment-app status to emulate tap-to-pay. The victim is induced to enter their payment-card PIN into a patched text field inside the app and then to hold their physical card against the back of the NFC-enabled phone. Captured NFC traffic is forwarded via HandyPay's existing relay channel to the operator device, which the attackers use to conduct contactless ATM withdrawals and unauthorised point-of-sale payments. Separately, the captured PIN is exfiltrated out-of-band over plain HTTP to the 108.165.230.223 C&C server, which doubles as the distribution host.

AI-ASSISTED CODE

ESET attributes the malicious code injection to likely GenAI tooling based on telltale emoji embedded in log strings and stylistic patterns typical of LLM-generated text. This is consistent with a broader 2025-2026 trend documented in ESET's H2 2025 Threat Report in which low-skill threat actors increasingly outsource malware authoring to LLMs, lowering the barrier to entry for NFC-relay fraud.

RELATIONSHIP TO PRIOR NGATE AND PHANTOMCARD CAMPAIGNS

NGate first became public in 2024 when ESET documented attacks against Czech banking customers relaying NFC traffic via the open-source NFCGate tool. The malware family diversified in 2025 with the PhantomCard variant that targeted Brazil using the NFU Pay MaaS to handle the relay, and similarly-named apps (including Card Protection-style branding) were observed as early as October 2025. The subject campaign diverges from both: the operator chose to patch the cheap (EUR 9.99/month donation-ware) HandyPay app instead of paying hundreds of USD per month for NFU Pay (~US$400/mo) or TX-NFC (~US$500/mo) MaaS subscriptions.

VICTIMOLOGY AND IMPACT

Confirmed victims are Android users in Brazil. Four compromised devices with captured PIN data were observed on the C&C server at time of analysis. Primary impact is direct financial loss via unauthorised ATM withdrawals and contactless payments. Secondary impact includes reputational damage to HandyPay, Caixa Economica Federal, Loterj, and Google Play. HandyPay has been notified by ESET and confirmed an internal investigation. Google has been notified through the App Defense Alliance and Google Play Protect detects known samples.

ATTRIBUTION

ESET has not attributed the campaign to a named actor. The shared hosting infrastructure and shared APK base imply a single operator or tightly-coordinated crew. Motivation is clearly financial (ATM cash-out) rather than espionage. Confidence in a single-actor operation is high; national attribution is unknown.

MITRE ATT&CK techniques used in TL-2026-0407

Defense Evasion

T1406 Obfuscated Files or Information; T1628 Hide Artifacts; T1655 Masquerading

Collection

T1409 Stored Application Data

Credential Access

T1417 Input Capture

Discovery

T1426 System Information Discovery

Command and Control

T1437 Application Layer Protocol; T1481 Web Service

Initial Access

T1476 Deliver Malicious App via Other Means; T1660 Phishing

Persistence

T1624 Event Triggered Execution

Impact

T1643 Generate Traffic from Victim

Exfiltration

T1646 Exfiltration Over C2 Channel

Execution

T1658 Exploitation for Client Execution

Affected products and versions in NGate Android NFC Relay Malware Variant

  • HandyPay — HandyPay Android App (trojanized copies only)
    Vulnerable versions: Patched/sideloaded variants distributed from protecaocartao.online since 2025-11
    Fixed in: Official Google Play version is NOT affected - only sideloaded trojanized copies
  • Google — Android (NFC payment stack)
    Vulnerable versions: All Android versions supporting Host Card Emulation and NFC where user sideloads trojanized APK
    Fixed in: Google Play Protect blocks known samples on devices with Play services

Remediation for NGate Android NFC Relay Malware Variant

Patches

  • No vendor patch available - malware abuses a legitimate third-party app (HandyPay). HandyPay developer has opened an internal investigation per ESET disclosure 2026-04-21
  • Google Play Protect updated with detection signatures for Android/Spy.NGate.CB and Android/Spy.NGate.CC

Immediate actions

  • Block domain protecaocartao.online and subdomains at DNS/proxy layer
  • Block outbound connections to 108.165.230.223 (C&C)
  • Hunt for SHA-1 48A0DE6A43FC6E49318AD6873EA63FE325200DBC, A4F793539480677241EF312150E9C02E324C0AA2, 94AF94CA818697E1D99123F69965B11EAD9F010C on managed Android endpoints
  • Verify Google Play Protect is enabled on all corporate Android fleet (auto-blocks known samples)
  • Alert Brazilian banking customers and retail users about the Rio de Premios lottery phishing lure and fake Protecao Cartao app
  • Audit which users have HandyPay installed outside of Google Play (sideloaded APKs) and quarantine those devices

Workarounds

  • Uninstall HandyPay entirely if obtained from any source other than Google Play
  • Disable NFC on Android devices when not in active use
  • Do not set any third-party app as the default payment application unless explicitly verified as Google Wallet or an issuer-approved wallet
  • Never enter a payment-card PIN into any mobile app - legitimate issuers never ask for PIN entry inside a payment app

Longer-term hardening

  • Deploy mobile EDR or MTD solution capable of detecting trojanized NFC relay apps on Android
  • Disable install from unknown sources via MDM policy on managed Android devices
  • Educate customers on NFC relay fraud patterns: apps requesting PIN entry plus card tap on phone are never legitimate issuer workflows
  • Monitor BIN usage at ATM cash-out hotspots for suspicious contactless withdrawal spikes
  • Implement transaction-pattern anomaly detection for contactless payments originating from unusual geolocations relative to the cardholder

Weaknesses (CWE) in NGate Android NFC Relay Malware Variant

CWE-494, CWE-913, CWE-345, CWE-829

Timeline of NGate Android NFC Relay Malware Variant

  • HandyPay NFC relay application first published on Google Play by legitimate developer, providing cross-device NFC card sharing for families
  • ESET Research publishes original NGate disclosure documenting NFCGate-based Android malware relaying payment card data in Czech banking attacks
  • PhantomCard variant of NGate observed in Brazil by ESET, using NFU Pay MaaS to facilitate NFC data transfer
  • Similar Protecao Cartao-style malicious apps observed in October 2025 campaigns targeting Brazil (PhantomCard precursor)
  • NGate trojanized HandyPay distribution site protecaocartao.online first observed on Cloudflare 104.21.91.170
  • NGate C&C server 108.165.230.223 (BattleHost, trading as KAUA REIS DA SILVA) first observed serving PIN exfiltration endpoint
  • Trojanized HandyPay NGate campaign begins active distribution through fake Rio de Premios lottery and fake Google Play Protecao Cartao pages
  • ESET researchers access attacker C&C and enumerate logs from four compromised Android devices in Brazil containing captured PINs, IPs and timestamps
  • ESET publishes detailed public analysis of new NGate variant on WeLiveSecurity, notifies Google via App Defense Alliance and HandyPay developer
  • Threadlinqs Intelligence publishes TL-2026-0407 threat record with full MITRE mapping, IOCs, detections and simulation coverage
  • As of 2026-05-29, this NGate trojanized-HandyPay NFC relay campaign (ESET, disclosed 2026-04-21, active since Nov 2025) remains a live threat in Brazil with no reported takedown, arrest, or sinkhole and no vendor patch (it abuses a legit app). It sits in a surging 2025-2026 NFC-relay fraud wave (PhantomCard, RelayNFC) accelerated by AI-assisted malware.

Sources cited for NGate Android NFC Relay Malware Variant

Threats related to NGate Android NFC Relay Malware Variant

Detection coverage for TL-2026-0407

As of 2026-04-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0407 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats