# NFCShare Android Malware Resurfaces with Sophisticated NFC Card-Skimming Attacks Targeting European Banks


Researchers have identified a resurgence of NFCShare, an evolving Android malware variant that exploits near-field communication (NFC) capabilities to steal payment card data from unsuspecting victims across Europe. The latest campaign, which began in May 2026, combines social engineering with technical sophistication to distribute malicious banking apps through GitHub repositories, marking a notable escalation in both distribution tactics and targeting scope.


## The Threat


NFCShare represents a specialized category of Android malware designed to weaponize legitimate NFC technology for financial fraud. Unlike traditional banking trojans that focus on credentials or session tokens, NFCShare takes a more direct approach: it extracts payment card data directly from physical cards by leveraging NFC-enabled Android devices.


The malware operates by presenting victims with a deceptive "verification screen" that prompts them to hold their payment card near their Android device's NFC chip. Under the guise of a security procedure, the victim complies, and the malware reads the card's sensitive information using Android's IsoDep interface and EMV commands. What the victim believes is a legitimate bank security check is actually a card-skimming operation.


Data stolen by NFCShare includes:

  • Primary Account Number (PAN)
  • Card type
  • Expiration date
  • 4-digit PIN (entered by the victim during the "verification" prompt)

  • Once exfiltrated, this data is transmitted to attacker-controlled command-and-control (C2) infrastructure via WebSocket channels, where it can be monetized through NFC payment relay schemes or sold on underground marketplaces.


    ## Background and Context


    D3Lab researchers first documented NFCShare in January 2026, initially tracking it as a relatively limited threat targeting Deutsche Bank customers in Germany. However, the malware's developers have been actively refining and expanding the threat since its discovery.


    The current NFCShare campaign demonstrates significant evolution:


  • Expanded targeting scope: From a single German bank to multiple financial institutions across Italy and Spain
  • Improved distribution: Moving from direct malware delivery to sophisticated phishing infrastructure
  • Enhanced evasion: Implementation of malformed APK packaging designed to frustrate automated analysis tools
  • Broader attack surface: The same threat actors appear to be developing variants and adapting tactics based on geographic regions

  • While D3Lab researchers note that NFCShare exhibits distinct code architecture and implementation details, they suggest the malware may represent an evolution of a broader threat ecosystem rather than an entirely novel development. The sophisticated social engineering, targeted approach, and technical capabilities suggest a well-resourced threat actor with specific knowledge of European banking infrastructure.


    ## Technical Details: How NFCShare Steals Card Data


    Understanding NFCShare's technical operation reveals why it poses a unique challenge for both defenders and users.


    The NFC attack flow:


    1. Social engineering vector — Victim is directed to a phishing website impersonating their bank

    2. Credential harvesting — Victim unknowingly provides banking credentials to the attacker

    3. Malware delivery — Victim is directed to download a fake banking app update from a GitHub repository

    4. Installation — Victim installs the malicious APK, believing it's a legitimate bank app

    5. Card interaction — Malware displays a convincing "security verification" screen requesting NFC card scan

    6. Data extraction — Malware reads card data via Android's IsoDep interface using EMV commands

    7. PIN capture — Additional screen captures 4-digit PIN under pretense of security check

    8. Exfiltration — Card data and PIN are transmitted to C2 server over WebSocket


    Why this attack is effective:


    The attack exploits a fundamental trust gap. Victims expect their banking apps to request verification steps. NFC card scanning, while unusual, appears plausible as a modern security measure. The malware abuses Android's legitimate NFC APIs to perform operations that appear indistinguishable from normal banking app behavior.


    Evasion techniques:


    Recent NFCShare variants incorporate malformed APK packaging to hinder automated malware analysis. While APK files remain valid ZIP archives, newer samples contain intentionally corrupted or poisoned file paths that cause certain automated extraction tools to fail or misinterpret relative paths as filesystem paths, triggering parsing errors.


    However, this technique only complicates static analysis in specific tools. Manual analysis and code recovery remain feasible, indicating the malware authors are optimizing for speed rather than unbreakable obfuscation—suggesting they expect rapid deployment and monetization before security tools catch up.


    ## Distribution Infrastructure and Campaign Details


    The current NFCShare campaign demonstrates sophisticated operational security and geographic targeting.


    GitHub-hosted malware distribution:


    A GitHub repository created on April 10, 2026, has hosted 56 distinct malicious APK files impersonating banking applications. The repository structure mirrors legitimate banking app distribution, making it appear credible to victims directed through phishing links.


    Targeted financial institutions (primarily Italy and Spain):


    | Bank / Service | Number of Variants Observed |

    |---|---|

    | Intesa Carte | Multiple |

    | Banca Sella | Multiple |

    | Sella Carte | Multiple |

    | Nexi Carte | Multiple |

    | Fideuram Carte | Multiple |

    | Mooney | Multiple |

    | CaixaBank (Spanish) | Multiple |

    | CaixaBank NFC | Multiple |

    | CaixaReactiva Tarjeta (Spanish) | Multiple |


    Attack initiation methods:


  • Primary: Phishing websites impersonating legitimate banks, requesting credentials and directing to "app update"
  • Secondary (suspected but not directly observed): SMS messages or phone calls from fake bank representatives, requesting device updates or verification

  • The geographic concentration on Italian and Spanish financial institutions suggests the threat actors possess regional focus or have identified specific security gaps in these markets.


    ## Implications for Financial Institutions and Users


    For financial institutions:


  • Direct fraud losses: Stolen card data enables both NFC relay attacks (documented in NGate, SuperCard X, and RelayNFC campaigns) and fraudulent purchases
  • Credential compromise: Phishing component of campaign captures banking usernames and passwords
  • Reputational damage: Customers experience fraud despite using apps they believed were official
  • Regulatory exposure: Data breaches involving payment card data trigger PCI DSS, GDPR, and regional financial regulations

  • For consumers:


  • Payment card fraud: Stolen data enables fraudulent charges and fraudulent transfers
  • Identity theft risk: Combined with phishing-harvested credentials, creates comprehensive account takeover risk
  • Limited fraud visibility: NFC-based card theft may not trigger immediate fraud alerts, allowing attackers to conduct multiple transactions

  • The sophistication of the attack—combining phishing, malware, and direct hardware interaction—makes it particularly difficult for fraud detection systems to prevent, as the initial card read appears legitimate to NFC readers.


    ## Recommendations


    For Android users:


  • Source banking apps exclusively from Google Play Store — Never download banking apps from email links, third-party app stores, or GitHub repositories
  • Enable Google Play Protect — Provides real-time scanning and detection of known malware
  • Verify app authenticity — Before updating a banking app, verify the update through your bank's official website or phone number, not through app notifications
  • Be skeptical of "verification requests" — Legitimate banks rarely request NFC card scans via their apps. If an app requests this, contact your bank immediately
  • Monitor financial accounts actively — Check bank and card statements regularly for unauthorized transactions

  • For financial institutions:


  • Implement behavioral analysis — Detect unusual NFC card reading patterns from authenticated sessions
  • Strengthen app distribution verification — Implement certificate pinning and cryptographic verification of app updates
  • Monitor for impersonation — Use brand monitoring and phishing detection services to identify fake banking domains
  • Educate customers — Launch targeted awareness campaigns about NFC skimming and app verification
  • Implement transaction velocity limits — Restrict rapid consecutive NFC payments to reduce fraud impact

  • For security teams:


  • Monitor GitHub for malicious APKs — Establish automated scanning of public repositories for banking malware signatures
  • Track NFC-based threats — Correlate NFCShare activity with known NFC relay attacks (NGate, SuperCard X, RelayNFC)
  • Update detection rules — Deploy yara rules and signatures for NFCShare's malformed APK packaging technique
  • Threat intelligence sharing — Contribute sightings to banking sector ISACs and MITRE ATT&CK framework

  • ---


    ## HackWire Analysis


    The resurgence of NFCShare highlights a critical evolution in Android banking malware: the shift from remote credential theft to direct hardware exploitation. Traditional mobile banking trojans rely on intercepting credentials or hijacking sessions—approaches that modern banking apps defend against through certificate pinning, biometric authentication, and cryptographic verification. NFCShare sidesteps these defenses entirely by operating at the payment card layer rather than the digital authentication layer.


    What makes this campaign particularly alarming is the geographic escalation. In January, the threat was limited to Deutsche Bank. By May, the same malware ecosystem had expanded across at least nine financial institutions in Italy and Spain—suggesting either significant market opportunity or deliberate campaign expansion. The precision of targeting European banks, the use of locale-specific app names (CaixaBank, Intesa Selle), and the GitHub distribution infrastructure indicate a well-resourced group operating with knowledge of regional banking practices.


    The malformed APK packaging technique reveals another insight: the attackers are optimizing for deployment speed, not stealth. By introducing corruption that breaks some automated analysis tools but not others, the malware authors are essentially "raising the cost" of detection without implementing truly robust obfuscation. This suggests confidence in rapid monetization before security tools catch up—a pattern consistent with crimeware operations targeting financial data.


    For defenders, the critical takeaway is that NFC-based card data theft bypasses most fraud detection systems designed around transaction patterns. A legitimate payment card transaction conducted over NFC relay networks appears identical to authorized payments. The only detection window is at malware installation—making app source verification and user education the only reliable controls.


    Organizations in targeted geographies should treat this as an elevated risk requiring customer communication, app security hardening, and increased monitoring of NFC-based fraud patterns. For users, the safest practice remains simple: legitimate banks never ask you to scan your card into your phone.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)