Threat reportMalwareTL-2026-0741
NFCShare Android Banking Malware Steals EMV Card Data and PINs via Weaponized European Banking Apps (com.modol.nap)
NFCShare Android Banking Malware Steals EMV Card Data and (TL-2026-0741), also tracked as NFCShare, is a high-severity malware campaign, first published 2026-06-09. It has no confirmed attribution, affects Google Android (NFC-enabled devices), maps to 17 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-0741
- Threat ID
- TL-2026-0741
- Also known as
- NFCShare, PhantomCard
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- financial, banking, consumer, retail-payments
- Target regions
- Europe, Italy, Spain, Germany
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in NFCShare Android Banking Malware Steals EMV Card Data and
Malware and tooling: NFCShare, OkHttp WebSocket
How NFCShare Android Banking Malware Steals EMV Card Data and works
NFCShare is an Android banking trojan distributed as fake versions of legitimate European banking apps through phishing sites and a GitHub repository disguised as a school project. It abuses the device NFC reader (android.nfc.tech.IsoDep) and EMV APDU commands to extract payment card data (PAN, type, label, expiry), then harvests the cardholder PIN through a fake WebView verification screen and exfiltrates both over a WebSocket C2 channel for use in NFC relay cash-out fraud.
NFCShare is a financially motivated Android malware family first documented in January 2026 by D3Lab researcher Andrea Draghetti, initially impersonating Deutsche Bank. Beginning 14 May 2026 the campaign pivoted and expanded to target customers of multiple Italian and broader European financial institutions, including Intesa Sanpaolo, Banca Sella, Fideuram, Nexi, Mooney, BCC Roma, Klirway and the Spanish bank CaixaBank.
The infection chain begins with phishing websites that mimic legitimate bank portals (e.g. areaclienti-intesa.com impersonating Intesa Sanpaolo). After a victim enters credentials, the site instructs them to perform a "mandatory update" of their banking application, delivering a malicious APK. Payloads are hosted both on the phishing infrastructure (via shortened links such as tinyurl.com/Intesa-Carte) and on a GitHub repository, github.com/antoniocastaldo1998/app-scuola, created on 10 April 2026 and disguised as a school project ("app-scuola"). As of early June 2026 the repository contained 57 commits and 56 unique APK payloads, demonstrating an aggressive rebuild-and-republish cadence.
Once installed, the application (primary package com.modol.nap; internal namespace nfc.share.itnamteis) displays a fake card-verification screen that prompts the victim to tap their physical payment card against the phone. NFCShare uses Android's IsoDep interface and standard EMV protocol commands — including PPSE (Proximity Payment System Environment) selection and EMV APDU exchanges — to read the card number (PAN), card type, label and expiry date directly from the contactless chip. A subsequent fake WebView screen with a progress indicator and PIN prompt captures the victim's 4-digit PIN.
Captured data is assembled into a simple ampersand-separated string and transmitted, with card data and PIN sent separately, over an OkHttp-based WebSocket channel to attacker command-and-control servers. Observed C2 endpoints are ws://38.47.213.197:7068/ (earlier builds) and ws://nfck.loseyourip.com:8001/ (more recent builds). The stolen EMV data is intended for NFC relay / card-emulation cash-out schemes consistent with the broader NGate, SuperCard X and RelayNFC ecosystem, though NFCShare uses distinct code, libraries and architecture and is tracked as a separate family (also referenced as PhantomCard/NFCShare).
Newer builds show deliberate anti-analysis tradecraft: an increased DEX count (10 versus 8), hardcoded obfuscation keys, and intentionally malformed ZIP entries with poisoned file paths designed to break naive extraction tooling while sophisticated analyzers such as JADX and apkInspector still function. Distinctive hunting markers include the nfc.share.itnamteis namespace, the CardInfoitmanteis card-info model class, and MQTT-style channel enumerations CARD_INFO_CHANNEL and SEND_CHANNEL.
MITRE ATT&CK techniques used in TL-2026-0741
Collection
T1005 Data from Local System; T1119 Automated Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
Execution
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities
Impact
stealth
Affected products and versions in NFCShare Android Banking Malware Steals EMV Card Data and
- Google — Android (NFC-enabled devices)
Vulnerable versions: Android devices with NFC and sideloading enabled - Intesa Sanpaolo — Mobile banking customers (impersonated)
Vulnerable versions: Targeted brand - CaixaBank — Mobile banking customers (impersonated)
Vulnerable versions: Targeted brand
Remediation for NFCShare Android Banking Malware Steals EMV Card Data and
Immediate actions
- Block C2 indicators at the perimeter: 38.47.213.197:7068 and nfck.loseyourip.com:8001 (WebSocket ws://)
- Block phishing domain areaclienti-intesa.com and the tinyurl.com/Intesa-Carte redirect
- Alert customers to only install banking apps from official app stores; banks never ask users to tap their card against the phone to 'verify' it
- Report and request takedown of github.com/antoniocastaldo1998/app-scuola and associated APK payloads
Workarounds
- Disable installation from unknown sources on Android devices
- Use Google Play Protect and keep it enabled
- Do not enter card PINs into any app outside the official bank application
Longer-term hardening
- Deploy mobile threat defense (MTD)/EDR with behavioral detection for sideloaded APKs that combine NFC IsoDep usage with WebView credential prompts
- Enforce 'block install from unknown sources' policy on managed Android fleets
- Bank-side: monitor for NFC relay / card-present-anomaly transaction patterns and add velocity/geo controls
- Customer education on phishing-driven 'mandatory update' social engineering
Timeline of NFCShare Android Banking Malware Steals EMV Card Data and
- NFCShare first documented by D3Lab researcher Andrea Draghetti, with initial targeting limited to Deutsche Bank customers in Germany.
- GitHub repository github.com/antoniocastaldo1998/app-scuola created, disguised as a school project ('app-scuola') to host malicious APK payloads.
- Targeting concentrates on banking customers primarily in Italy and Spain via brand-specific weaponized apps (e.g. IntesaCarte, NexiCarte, CaixaBank).
- Recent wave of attacks begins: campaign pivots and expands to Italian and broader European banks (Intesa Sanpaolo, Banca Sella, Fideuram, Nexi, Mooney, BCC Roma, Klirway, CaixaBank), routing phishing-site victims to the GitHub repo for the malicious APK.
- Newer NFCShare builds add anti-analysis tradecraft: increased DEX count (10 vs 8), hardcoded obfuscation keys, and intentionally malformed ZIP/APK entries with poisoned file paths to break naive extraction tooling.
- GitHub repository observed hosting 57 commits and 56 unique APK payloads, demonstrating an aggressive rebuild-and-republish cadence.
- BleepingComputer publishes reporting on NFCShare spreading via fake banking app updates hosted on GitHub.
- Further public reporting (Cyber Security News, GBHackers, CyberPress, Reconbee) details NFCShare NFC/EMV TTPs, IOCs, WebSocket C2 channels and anti-analysis packaging.
Sources cited for NFCShare Android Banking Malware Steals EMV Card Data and
- New NFCShare Android Malware Delivered via Weaponized Versions of Legitimate Banking Apps
- NFCShare Android malware spreads via fake banking app updates on GitHub
- NFCShare Android Malware Spreads via Weaponized Banking Apps
- Cybercriminals Weaponize Banking Apps to Spread NFCShare Malware
- NFCShare Android malware spreads via fake banking app updates on GitHub (Reconbee)
- PhantomCard/NFCShare Banking Trojan (Android) - removal guide
Detection coverage for TL-2026-0741
As of 2026-06-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0741 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.