• News/
  • https://www.bleepingcomputer.com/news/security/massive-surge-of-nfc-relay-malware-steals-europeans-credit-cards/

Massive surge of NFC relay malware steals Europeans’ credit cards

BleepingComputer
·
Bill Toulas
·
Published Oct 30, 2025
·
Updated

Near-Field Communication (NFC) relay malware has grown massively popular in Eastern Europe, with researchers discovering over 760 malicious Android apps using the technique to steal people's payment card information in the past few months. Contrary to the traditional banking trojans that use overlays to steal banking credentials or remote access tools to perform fraudulent transactions, NFC malware abuses Android's Host Card Emulation (HCE) to emulate or steal contactless credit card and payment data. They capture EMV fields, respond to APDU commands from a POS terminal with attacker-controlled replies, or forward terminal requests to a remote server, which crafts the proper APDU responses to enable payments at the terminal without the physical cardholder present. The technique was spotted in the wild for the first time in 2023 in Poland, followed by campaigns in the Czech Republic, and later, more massive attack waves in Russia. Over time, multiple variants emerged following different practical approaches, including: According to mobile security firm Zimperium, a member of Google's 'App Defense Alliance,' the popularity of NFC malware on Android has exploded lately, particularly in Eastern Europe. "What began as just a few isolated samples has now expanded to more than 760 malicious apps observed in the wild—demonstrating that NFC relay abuse is not slowing down but continuing to accelerate," explains Zimperium. "Campaigns previously documented by other vendors are now broa...

Read full article

Affected Software

1 affected component
Android Android
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a significant increase in NFC relay malware targeting credit card information in Eastern Europe.

2

What security implications are discussed?

The rise of NFC relay malware poses a serious threat to users' payment card data, leading to potential financial losses.

3

What regions are primarily affected by this surge of malware?

The surge of NFC relay malware is primarily seen in Eastern Europe.

4

How many malicious Android apps have been discovered using this technique?

Researchers have identified over 760 malicious Android apps leveraging NFC relay malware.

5

What platform is affected by the NFC relay malware?

The affected platform is Android, with malicious apps specifically targeting Android devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203