🚨 Tracking the Rise of Chinese Tap-to-Pay Android Malware
Tap-to-pay fraud is no longer limited to stolen cards or physical proximity. Threat actors are now abusing NFC-enabled
#Androidmalware to relay
#paymentdata in real time, enabling remote, contactless fraud at scale. Our latest research uncovers how Chinese
#cybercrime communities are industrializing this technique and turning it into a fully operational fraud ecosystem.
Key Highlights:
🔹 Over 54 NFC-enabled Android malware samples identified, designed to relay payment APDUs remotely
🔹 Multiple Telegram-based vendors offering tap-to-pay malware as a service, complete with subscriptions, support, and custom regional builds
🔹 At least $355,000 in fraudulent transactions linked to a single illicit POS vendor between Nov 2024 and Aug 2025
🔹
#Smishing and
#vishing campaigns actively used to trick victims into installing malware and tapping their cards
🔹 Mule networks and compromised mobile wallets enabling global, card-present fraud without physical cards
Alongside these findings, the research provides in-depth technical analysis of TX-NFC,
#NFU, and related variants, examining code overlaps, cash-out infrastructure, and key defensive considerations for
#financialinstitutions and payment networks. Read the full research now:
link.group-ib.com/3Li56bI