# NFCShare Android Malware Resurfaces with Sophisticated NFC Card-Skimming Attacks Targeting European Banks
Researchers have identified a resurgence of NFCShare, an evolving Android malware variant that exploits near-field communication (NFC) capabilities to steal payment card data from unsuspecting victims across Europe. The latest campaign, which began in May 2026, combines social engineering with technical sophistication to distribute malicious banking apps through GitHub repositories, marking a notable escalation in both distribution tactics and targeting scope.
## The Threat
NFCShare represents a specialized category of Android malware designed to weaponize legitimate NFC technology for financial fraud. Unlike traditional banking trojans that focus on credentials or session tokens, NFCShare takes a more direct approach: it extracts payment card data directly from physical cards by leveraging NFC-enabled Android devices.
The malware operates by presenting victims with a deceptive "verification screen" that prompts them to hold their payment card near their Android device's NFC chip. Under the guise of a security procedure, the victim complies, and the malware reads the card's sensitive information using Android's IsoDep interface and EMV commands. What the victim believes is a legitimate bank security check is actually a card-skimming operation.
Data stolen by NFCShare includes:
Once exfiltrated, this data is transmitted to attacker-controlled command-and-control (C2) infrastructure via WebSocket channels, where it can be monetized through NFC payment relay schemes or sold on underground marketplaces.
## Background and Context
D3Lab researchers first documented NFCShare in January 2026, initially tracking it as a relatively limited threat targeting Deutsche Bank customers in Germany. However, the malware's developers have been actively refining and expanding the threat since its discovery.
The current NFCShare campaign demonstrates significant evolution:
While D3Lab researchers note that NFCShare exhibits distinct code architecture and implementation details, they suggest the malware may represent an evolution of a broader threat ecosystem rather than an entirely novel development. The sophisticated social engineering, targeted approach, and technical capabilities suggest a well-resourced threat actor with specific knowledge of European banking infrastructure.
## Technical Details: How NFCShare Steals Card Data
Understanding NFCShare's technical operation reveals why it poses a unique challenge for both defenders and users.
The NFC attack flow:
1. Social engineering vector — Victim is directed to a phishing website impersonating their bank
2. Credential harvesting — Victim unknowingly provides banking credentials to the attacker
3. Malware delivery — Victim is directed to download a fake banking app update from a GitHub repository
4. Installation — Victim installs the malicious APK, believing it's a legitimate bank app
5. Card interaction — Malware displays a convincing "security verification" screen requesting NFC card scan
6. Data extraction — Malware reads card data via Android's IsoDep interface using EMV commands
7. PIN capture — Additional screen captures 4-digit PIN under pretense of security check
8. Exfiltration — Card data and PIN are transmitted to C2 server over WebSocket
Why this attack is effective:
The attack exploits a fundamental trust gap. Victims expect their banking apps to request verification steps. NFC card scanning, while unusual, appears plausible as a modern security measure. The malware abuses Android's legitimate NFC APIs to perform operations that appear indistinguishable from normal banking app behavior.
Evasion techniques:
Recent NFCShare variants incorporate malformed APK packaging to hinder automated malware analysis. While APK files remain valid ZIP archives, newer samples contain intentionally corrupted or poisoned file paths that cause certain automated extraction tools to fail or misinterpret relative paths as filesystem paths, triggering parsing errors.
However, this technique only complicates static analysis in specific tools. Manual analysis and code recovery remain feasible, indicating the malware authors are optimizing for speed rather than unbreakable obfuscation—suggesting they expect rapid deployment and monetization before security tools catch up.
## Distribution Infrastructure and Campaign Details
The current NFCShare campaign demonstrates sophisticated operational security and geographic targeting.
GitHub-hosted malware distribution:
A GitHub repository created on April 10, 2026, has hosted 56 distinct malicious APK files impersonating banking applications. The repository structure mirrors legitimate banking app distribution, making it appear credible to victims directed through phishing links.
Targeted financial institutions (primarily Italy and Spain):
| Bank / Service | Number of Variants Observed |
|---|---|
| Intesa Carte | Multiple |
| Banca Sella | Multiple |
| Sella Carte | Multiple |
| Nexi Carte | Multiple |
| Fideuram Carte | Multiple |
| Mooney | Multiple |
| CaixaBank (Spanish) | Multiple |
| CaixaBank NFC | Multiple |
| CaixaReactiva Tarjeta (Spanish) | Multiple |
Attack initiation methods:
The geographic concentration on Italian and Spanish financial institutions suggests the threat actors possess regional focus or have identified specific security gaps in these markets.
## Implications for Financial Institutions and Users
For financial institutions:
For consumers:
The sophistication of the attack—combining phishing, malware, and direct hardware interaction—makes it particularly difficult for fraud detection systems to prevent, as the initial card read appears legitimate to NFC readers.
## Recommendations
For Android users:
For financial institutions:
For security teams:
---
## HackWire Analysis
The resurgence of NFCShare highlights a critical evolution in Android banking malware: the shift from remote credential theft to direct hardware exploitation. Traditional mobile banking trojans rely on intercepting credentials or hijacking sessions—approaches that modern banking apps defend against through certificate pinning, biometric authentication, and cryptographic verification. NFCShare sidesteps these defenses entirely by operating at the payment card layer rather than the digital authentication layer.
What makes this campaign particularly alarming is the geographic escalation. In January, the threat was limited to Deutsche Bank. By May, the same malware ecosystem had expanded across at least nine financial institutions in Italy and Spain—suggesting either significant market opportunity or deliberate campaign expansion. The precision of targeting European banks, the use of locale-specific app names (CaixaBank, Intesa Selle), and the GitHub distribution infrastructure indicate a well-resourced group operating with knowledge of regional banking practices.
The malformed APK packaging technique reveals another insight: the attackers are optimizing for deployment speed, not stealth. By introducing corruption that breaks some automated analysis tools but not others, the malware authors are essentially "raising the cost" of detection without implementing truly robust obfuscation. This suggests confidence in rapid monetization before security tools catch up—a pattern consistent with crimeware operations targeting financial data.
For defenders, the critical takeaway is that NFC-based card data theft bypasses most fraud detection systems designed around transaction patterns. A legitimate payment card transaction conducted over NFC relay networks appears identical to authorized payments. The only detection window is at malware installation—making app source verification and user education the only reliable controls.
Organizations in targeted geographies should treat this as an elevated risk requiring customer communication, app security hardening, and increased monitoring of NFC-based fraud patterns. For users, the safest practice remains simple: legitimate banks never ask you to scan your card into your phone.
— HackWire Editorial
---
## Related Coverage