# NFCShare Android Banking Malware Steals EMV Card Data and PINs via Weaponized European Banking Apps (com.modol.nap)

> NFCShare is an Android banking trojan distributed as fake versions of legitimate European banking apps through phishing sites and a GitHub repository disguised as a school project. It abuses the device NFC reader (android.nfc.tech.IsoDep) and EMV APDU commands to extract payment card data (PAN, type, label, expiry), then harvests the cardholder PIN through a fake WebView verification screen and exfiltrates both over a WebSocket C2 channel for use in NFC relay cash-out fraud.

- **Published:** 2026-06-09T00:00:00Z
- **Last reviewed:** 2026-06-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0741
- **ID:** TL-2026-0741
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

NFCShare is a financially motivated Android malware family first documented in January 2026 by D3Lab researcher Andrea Draghetti, initially impersonating Deutsche Bank. Beginning 14 May 2026 the campaign pivoted and expanded to target customers of multiple Italian and broader European financial institutions, including Intesa Sanpaolo, Banca Sella, Fideuram, Nexi, Mooney, BCC Roma, Klirway and the Spanish bank CaixaBank.

The infection chain begins with phishing websites that mimic legitimate bank portals (e.g. areaclienti-intesa.com impersonating Intesa Sanpaolo). After a victim enters credentials, the site instructs them to perform a "mandatory update" of their banking application, delivering a malicious APK. Payloads are hosted both on the phishing infrastructure (via shortened links such as tinyurl.com/Intesa-Carte) and on a GitHub repository, github.com/antoniocastaldo1998/app-scuola, created on 10 April 2026 and disguised as a school project ("app-scuola"). As of early June 2026 the repository contained 57 commits and 56 unique APK payloads, demonstrating an aggressive rebuild-and-republish cadence.

Once installed, the application (primary package com.modol.nap; internal namespace nfc.share.itnamteis) displays a fake card-verification screen that prompts the victim to tap their physical payment card against the phone. NFCShare uses Android's IsoDep interface and standard EMV protocol commands — including PPSE (Proximity Payment System Environment) selection and EMV APDU exchanges — to read the card number (PAN), card type, label and expiry date directly from the contactless chip. A subsequent fake WebView screen with a progress indicator and PIN prompt captures the victim's 4-digit PIN.

Captured data is assembled into a simple ampersand-separated string and transmitted, with card data and PIN sent separately, over an OkHttp-based WebSocket channel to attacker command-and-control servers. Observed C2 endpoints are ws://38.47.213.197:7068/ (earlier builds) and ws://nfck.loseyourip.com:8001/ (more recent builds). The stolen EMV data is intended for NFC relay / card-emulation cash-out schemes consistent with the broader NGate, SuperCard X and RelayNFC ecosystem, though NFCShare uses distinct code, libraries and architecture and is tracked as a separate family (also referenced as PhantomCard/NFCShare).

Newer builds show deliberate anti-analysis tradecraft: an increased DEX count (10 versus 8), hardcoded obfuscation keys, and intentionally malformed ZIP entries with poisoned file paths designed to break naive extraction tooling while sophisticated analyzers such as JADX and apkInspector still function. Distinctive hunting markers include the nfc.share.itnamteis namespace, the CardInfoitmanteis card-info model class, and MQTT-style channel enumerations CARD_INFO_CHANNEL and SEND_CHANNEL.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1585 Establish Accounts
- T1566 Phishing
- T1189 Drive-by Compromise
- T1204 User Execution
- T1027 Obfuscated Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1684.001 Impersonation
- T1056 Input Capture
- T1005 Data from Local System
- T1119 Automated Collection
- T1071 Application Layer Protocol
- T1102 Web Service
- T1573 Encrypted Channel
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft

## Sources

- [New NFCShare Android Malware Delivered via Weaponized Versions of Legitimate Banking Apps](https://cybersecuritynews.com/new-nfcshare-android-malware-delivered-via-weaponized-versions/)
- [NFCShare Android malware spreads via fake banking app updates on GitHub](https://www.bleepingcomputer.com/news/security/nfcshare-android-malware-spreads-via-fake-banking-app-updates-on-github/)
- [NFCShare Android Malware Spreads via Weaponized Banking Apps](https://gbhackers.com/nfcshare-android-malware/)
- [Cybercriminals Weaponize Banking Apps to Spread NFCShare Malware](https://cyberpress.org/banking-apps-spread-nfcshare/)
- [NFCShare Android malware spreads via fake banking app updates on GitHub (Reconbee)](https://www.reconbee.com/nfcshare-android-malware-spreads-via-fake-banking-app-updates-on-github/)
- [PhantomCard/NFCShare Banking Trojan (Android) - removal guide](https://www.pcrisk.com/removal-guides/35326-phantomcard-nfcshare-banking-trojan-android)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0741
