NGate and NFC Relay Threats

Understanding the NGate Malware Threat

NGate is a new type of Android malware that represents one of the most sophisticated contactless payment fraud techniques seen in the wild. Rather than stealing credentials or looking for software bugs, NGate leverages Near-Field Communication (NFC) to directly capture and relay payment card data from an infected device to an attacker’s device. This makes it possible for criminals to withdraw cash or make transactions without ever physically stealing a card.

Security researchers first identified NGate targeting banking customers in Europe in late 2023 and into 2024. Attackers used deceptive phishing campaigns to trick victims into installing malicious apps that appeared to come from their bank. Once installed, the malware instructed victims to enable NFC and place their real payment card near their phone, at which point the malware captured the card’s NFC data and relayed it to devices controlled by the attackers waiting at ATMs or other terminals.

How the NFC Relay Attack Works

What makes NGate unique is its use of a relay attack, a technique where communication between two systems (like a card and a payment terminal) is intercepted and forwarded so that the attacker’s system can impersonate the legitimate party. NFC relay attacks have long been a theoretical concern in mobile security research: attackers can forward NFC exchanges in real time, tricking systems into accepting fraudulent contactless inputs.

In NGate’s case, the malware uses the victim’s own Android phone as the relay point. After installation via phishing messages and fake bank notifications, the malware registers itself with Android’s NFC/HCE (Host Card Emulation) framework to capture sensitive card information when the victim complies with the scammer’s prompts. That information, including the card’s NFC traffic and PIN entry, is sent to a remote attacker device that then emulates the card at an ATM or point-of-sale terminal, enabling unauthorized transactions.

The Human and Technical Elements Combined

NGate’s campaign shows how attackers blend social engineering and technical exploitation to bypass traditional security measures. Victims are typically convinced through SMS, email phishing, or even follow-up phone calls, impersonating bank staff, to install the malware and perform actions that enable the attack.

This combination of deception with a legitimate NFC channel makes NGate more dangerous than typical online scams. It doesn’t rely on exploiting a software flaw; instead, it abuses the legitimate NFC communication protocols built into Android and payment cards for malicious purposes.

Why Physical Protection Still Matters

While most discussions about mobile threats focus on software and digital defenses, the NGate example highlights an under-appreciated layer of risk: the wireless contactless communication itself. NFC and RFID signals are broadcast at very close range, and that’s exactly what attackers leverage, whether through malware relay, rogue readers, or physical skimming, to capture sensitive card data.

This is where RFID/NFC shielding products remain relevant. A shielded wallet, sleeve, or case doesn’t stop a phishing attack or prevent software from being installed, but it does block unauthorized NFC reads when your card is not intentionally presented to a terminal. If a card’s wireless signal can’t be emitted in the first place, there’s nothing for malware or unauthorized readers to capture or relay.

A Layered Defense Is Essential

NGate serves as a real-world reminder that contactless systems combine physical and digital components, and attackers will continue to exploit any gap between them. Protecting your cards starts with good digital habits, only install trusted apps, avoid suspicious links, and keep your device security up to date, but physical signal protection adds an important, independent layer of defense.

Using RFID/NFC shielding products helps ensure that your contactless cards are only read when you intend them to be. When combined with mindful digital practices, this layered approach gives users stronger defense against both traditional skimming and emerging hybrid threats like NGate.

Produits RFID en vedette

Secure Badge Holder DuoLite ® Vertical 2 ID Card Holder - Clear - IDSH2004 - 001B - Clr
Porte-badge sécurisé DuoLite ® Vertical 2 Porte-carte d'identité
+9
+8
+7
+6
+5
+4
+3
+2
+1
Prix réduit$7.99 USD
$7.99 / item
50 avis
En stock

Portefeuilles RFID les plus vendus, porte-badges blindés, pochettes de blocage RFID

Voir tout
Secure Badge Holder DuoLite ® Vertical 2 ID Card Holder - Clear - IDSH2004 - 001B - Clr
Porte-badge sécurisé DuoLite ® Vertical 2 Porte-carte d'identité
+9
+8
+7
+6
+5
+4
+3
+2
+1
Prix réduit$7.99 USD
$7.99 / item
50 avis
En stock
"Squeeze to Read" Secure Badge Holder Classic Vertical 1 ID Card Holder - Clear - IDSH1004 - 001B - Clr
Porte-badge sécurisé « Squeeze to Read » Classic Vertical 1 Porte-carte d'identité
+9
+8
+7
+6
+5
+4
+3
+2
+1
Prix réduit$8.49 USD
$8.49 / item
29 avis
En stock
36 " Breakaway Lanyard for ID Badge Holders - Black - IDSH1008 - Blk
Lanière détachable de 36 po pour porte-badges d'identification
+10
+9
+8
+7
+6
+5
+4
+3
+2
+1
Prix réduit$1.99 USD
0 avis
En stock
RFID Wallet Dual Portrait ID Leather Badge Holder - Black - IDSH7007 - blk
Portefeuille RFID Porte-badge en cuir à double portrait
+3
+2
+1
Prix réduit$18.99 USD
15 avis
En stock
Secure Badge Holder Lite ™ Vertical 1 ID Card Holder - Clear - IDSH9001 - 001B - Clr
Secure Badge Holder Lite ™ Vertical 1 Porte-carte d'identité
+8
+7
+6
+5
+4
+3
+2
+1
Prix réduit$5.99 USD
$5.99 / item
1 avis
En stock
Secure Badge Holder Classic Vertical 1 ID Card Holder, and Lanyard Bundle - Black - IDSH1038 - blkblk
Porte-badge sécurisé Classic Vertical 1 porte-carte d'identité et cordon
+4
+3
+2
+1
Prix réduit$9.49 USD
$9.49 / item
5 avis
En stock
Secure Badge Holder DuoLite ® is a horizontal id badge holder that holds 2 cards.  Blue - IDSH2004 - 002B - Blu
Porte-badge sécurisé DuoLite ® Porte-carte d'identité horizontal 2
+4
+3
+2
+1
Prix réduit$7.99 USD
$7.99 / item
2 avis
En stock
Secure Badge Holder Duolite ® Vertical 2 ID Card Holder, and Lanyard Bundle - Black - IDSH2038 - blkblk
Porte-badge sécurisé Duolite ® Vertical 2, porte-carte d'identité et cordon
+4
+3
+2
+1
Prix réduit$9.49 USD
$9.49 / item
2 avis
En stock