{"id":234368,"date":"2026-04-21T06:40:00","date_gmt":"2026-04-21T10:40:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/04\/21\/ngate-campaign-targets-brazil-trojanizes-handypay-to-steal-nfc-data-and-pins\/"},"modified":"2026-04-22T12:10:10","modified_gmt":"2026-04-22T16:10:10","slug":"ngate-campaign-targets-brazil-trojanizes-handypay-to-steal-nfc-data-and-pins","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/04\/21\/ngate-campaign-targets-brazil-trojanizes-handypay-to-steal-nfc-data-and-pins\/","title":{"rendered":"NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/ngate-campaign-targets-brazil.html\">NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/ngate-campaign-targets-brazil.html\">https:\/\/thehackernews.com\/2026\/04\/ngate-campaign-targets-brazil.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-04-21 06:40:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Apr 21, 2026<\/span><\/span><span class=\"p-tags\">Mobile Security \/ Artificial Intelligence<\/span><\/p>\n<p>Cybersecurity researchers have discovered a new iteration of an Android malware family called\u00a0<strong>NGate\u00a0<\/strong>that has been found to abuse a legitimate application called\u00a0HandyPay instead of NFCGate.<\/p>\n<p>&#8220;The threat actors took the app, which is used to relay NFC data, and patched it with malicious code that appears to have been AI-generated,&#8221; ESET security researcher Luk\u00e1\u0161 \u0160tefanko said in a report shared with The Hacker News. &#8220;As with previous iterations of NGate, the malicious code allows the attackers to transfer NFC data from the victim&#8217;s payment card to their own device and use it for contactless ATM cash-outs and unauthorized payments.&#8221;<\/p>\n<p>In addition, the malicious payload is capable of capturing the victim&#8217;s payment card PIN and exfiltrating it to the threat actor&#8217;s command-and-control (C2) server.<\/p>\n<p>NGate, also known as NFSkate, was first publicly documented by the Slovakian cybersecurity vendor in August 2024, detailing its ability to carry out relay attacks to siphon victims&#8217; contactless payment data with an aim to conduct fraudulent transactions.<\/p>\n<p>A year later, Dutch mobile security company ThreatFabric detailed a threat codenamed RatOn that used dropper apps impersonating adult-friendly versions of TikTok to deploy NGate to carry out NFC relay attacks.<\/p>\n<p>The latest version of NGate detected by ESET has primarily targeted users in Brazil, marking the first such campaign to single out the South American nation. The trojanized HandyPay application is distributed via websites masquerading as Rio de Pr\u00eamios, a lottery run by the Rio de Janeiro state lottery organization, and a Google Play Store listing page for a purported card protection app.<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"1603\" data-original-width=\"2000\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjRbKRbU7oozqgBvfx3vIWhYC8INgnuJtuBJF1WVByWuw4A8uFiVmjNBFLL-S1VGcCMr3m7dcIVs6tDUJCRMlboLSGeXAZHbQXqMCz-r5VG0W7gmKPZjO22S02HUX_08E7MyDafpzSZmcGXnOzfbMDP94U63JxDglu7VgWkDxQmWhlWRn-VZjeoL_nBI_Wm\/s1600\/camp.png\"\/><\/p>\n<p>The fake lottery website seeks to convince a user to tap a button to send a WhatsApp message to claim the prize money, at which point they are directed to likely download the poisoned version of the HandyPay app. Regardless of the method used, the app&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/ngate-campaign-targets-brazil.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs https:\/\/thehackernews.com\/2026\/04\/ngate-campaign-targets-brazil.html Publish Date:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":234369,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjcErEs-NVQwFX9tnOmYqQrfDjLm6WUB5jr8ltsA6bMOlVwmDwzBb5RbYAidS2jxdCPQ9RJtsgl453b7KbY8z_6tOjs0VIA7vF8LjM2OJqkZW8c1IM6TYwToxxp4dk8O0KiozATn5L4U40n2HK-Nya7tcimt1exRy9ZtYnri0XyMuM55W5AbC_8EAE0oDQC\/s1600\/android-nfc.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[26,20,24,35,32,34],"class_list":["post-234368","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ai","tag-artificial-intelligence","tag-cybersecurity","tag-hacker","tag-malware","tag-threat-actor"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/234368"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=234368"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/234368\/revisions"}],"predecessor-version":[{"id":234370,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/234368\/revisions\/234370"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/234369"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=234368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=234368"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=234368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}