Tuesday, April 28, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

ESET Research: New NGate hides in NFC payment app, possibly built with AI

April 21, 2026
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 6 mins read
5
SHARES
246
VIEWS
Share on TwitterShare on LinkedInShare on Facebook
  • ESET researchers discovered a new NGate malware variant abusing the legitimate Android HandyPay application.
  • To trojanize HandyPay, threat actors most likely used GenAI.
  • The campaign has been ongoing since November 2025 and targets Android users in Brazil.
  • ESET investigated two NGate samples being distributed in the attacks: one via a fake lottery website, the other through a fake Google Play website.

BRATISLAVA, Slovakia, April 21, 2026 (GLOBE NEWSWIRE) — ESET Research has discovered a new variant of the NGate malware family that abuses a legitimate Android application called HandyPay, instead of the previously leveraged NFCGate tool. The threat actors took the app, which is used to relay NFC data, and patched it with malicious code that appears to have been AI generated. As with previous iterations of NGate, the malicious code allows the attackers to transfer NFC data from the victim’s payment card to their own device and use them for contactless ATM cash-outs and unauthorized payments. Additionally, the code can capture the victims’ payment card PINs and exfiltrate them to the operators’ C&C server. The primary targets of this are users in Brazil; however, NFC-based attacks are expanding into new regions.

The malicious code used to trojanize HandyPay shows signs of having been produced with the help of GenAI tools. Specifically, the malware logs contain an emoji typical of AI-generated text, suggesting that LLMs were involved in generating or modifying the code, although definitive proof remains elusive. This fits a broader trend in which GenAI lowers the barrier to entry for cybercriminals, enabling threat actors with limited technical skill to produce workable malware.

ESET Research believes that the campaign distributing the trojanized HandyPay began around November 2025 and remains active. It should also be noted that the maliciously patched version of HandyPay has never been available on the official Google Play store. As an App Defense Alliance partner, we shared our findings with Google. ESET also reached out to the HandyPay developers to alert them about the malicious use of their application.

As the number of NFC threats keeps rising, so too has the ecosystem supporting them become more robust. The first NGate attacks employed the open-source NFCGate tool to facilitate the transfer of NFC data. Since then, several malware-as-a-service (MaaS) offerings with similar functionality have become available for purchase. However, in this campaign the threat actors decided to go with their own solution and maliciously patched an existing app – HandyPay.

“Why did the operators of this campaign decide to trojanize the HandyPay app instead of going with an established solution for relaying NFC data? The answer is simple: money. The subscription fees for existing MaaS kits run in the hundreds of dollars: NFU Pay advertises its product for almost US$400 per month, while TX-NFC goes for around US$500 per month. On the other hand, the legitimate HandyPay app is significantly cheaper, only asking for a €9.99 per month donation, if even that. In addition to the price, HandyPay natively does not require any permissions, only to be made the default payment app, helping the threat actors avoid raising suspicion,” says ESET researcher Lukáš Štefanko, who discovered the new NGate variant in the trojanized NFC payment app.

The first new NGate sample is distributed through a website that impersonates Rio de Prêmios, a lottery run by the Rio de Janeiro state lottery organization (Loterj). The second NGate sample is distributed via a fake Google Play web page as an app named Proteção Cartão (machine translation: Card Protection). Both sites were hosted on the same domain, strongly implying a single threat actor. The malware abuses the HandyPay service to forward NFC card data to an attacker-controlled device. Apart from relaying NFC data, the malicious code also steals payment card PINs, enabling the threat actor to use the victim’s payment card data to withdraw cash from ATMs.

For a more detailed analysis of the new NGate variant, check out the latest ESET Research blog post, “New NGate variant hides in a trojanized NFC payment app,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), Bluesky, and Mastodon for the latest news from ESET Research.

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown — securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit http://www.eset.com or follow our social media, podcasts and blogs.

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.
ShareTweet1ShareSendShare2
Previous Post

ISN® Celebrates 15 Years of Supporting Hiring Organisations and Contractors Across Europe

Next Post

ESET Research: New NGate hides in NFC payment app, possibly built with AI

Related Posts

Predictiv AI’s Shift Technologies Enters Strategic Joint Venture with Arcasia Holdings (Pvt) Ltd. to Deploy AI-Powered Logistics Platform Across Global First, Middle, and Last Mile Networks

TORONTO, ON / ACCESS Newswire / April 28, 2026 / Predictiv AI Inc. (CSE:PAI)(FWB:7IT) (the "Company" or "Predictiv AI"), is pleased to announce that its subsidiary, Shift Technologies ("Shift"), has entered into a strategic joint venture with Arcasia Holdings (Pvt) Ltd ("Arcasia Holdings"), a family office-founded and led by Aravinda...

Read moreDetails

Dynamite Deploys AI-Powered Identity Technology to Deliver Institutional-Grade Security at Consumer-Level Simplicity

The Company's Biometric AI-Driven Wallet utilizes Customer Identity to Unlock Digital Asset Self-Custody VANCOUVER, BC / ACCESS Newswire / April 28, 2026 / Dynamite Blockchain Corp. (the "Company" or "Dynamite") (CSE:KAS)(OTC:CRYBF) is pleased to announce that it will now be in a position to deploy AI-driven authentication technology to enable...

Read moreDetails

Optimus Launches Jared, an AI Sales Rep That Helps Logistics Teams Perform Like Their Top Sellers

Austin, TX, April 28, 2026 --(PR.com)-- Optimus today announced the launch of Jared, an AI sales agent designed to help logistics sales teams prospect with the same level of preparation and judgment as their top-performing rep.Most sales teams don't have a problem getting contacts. They have an execution problem. Reps still...

Read moreDetails

Consultwebs Releases 2026 Digital Marketing Predictions: Navigating GEO, E-E-A-T, and AI-Driven Search Volatility

Consultwebs Releases 2026 Digital Marketing Predictions: Navigating GEO, E-E-A-T, and AI-Driven Search VolatilityConsultwebs, the nation's premier legal digital marketing agency, is proud to announce the publication of its 2026 Digital Marketing Predictions for Law Firms. RALEIGH, NC, April 28, 2026 /24-7PressRelease/ -- This strategic guide is designed to help attorneys...

Read moreDetails

Tamar Toledano Highlights Cybersecurity Turning Point as Advanced AI Model Signals New Era of Digital Risk

Tamar Toledano Highlights Cybersecurity Turning Point as Advanced AI Model Signals New Era of Digital RiskAI-powered vulnerability discovery is accelerating cyber threats and forcing organizations to rethink security from reactive defense to real-time resilience LOS ANGELES, CA, April 28, 2026 /24-7PressRelease/ -- A newly unveiled artificial intelligence model with unprecedented...

Read moreDetails

Cactus Technology Solutions Private Limited has been Empanelled by National e-Governance Division to Support AI Capacity Building for Government Initiatives

MUMBAI, India, April 28, 2026 /PRNewswire/ -- Cactus Technology Solutions Private Limited (CACTUS),formerly known as Cactus Communications, has announced that it has been empanelled by National e-Governance Division (NeGD) under the Ministry of Electronics and Information Technology (MeitY), Government of India, as a partner agency to provide specialized AI/ML talent for...

Read moreDetails

Zurich launches Global Capability Center in Hyderabad to power next-gen tech and AI

HYDERABAD, India, April 28, 2026 /PRNewswire/ -- Zurich Insurance Group (Zurich) today announced the launch of a new Global Capability Center in Hyderabad, reinforcing its focus on advancing technology and AI capabilities to transform insurance. Zurich has appointed Amit Kalra as Head of Zurich Capability Centers, effective 1 July 2026....

Read moreDetails

Regula Receives 96/100 Customer Recommendation Score in Latest G2 Report

RESTON, Va, April 28, 2026 (GLOBE NEWSWIRE) -- Software review platform G2 has recognized Regula, a global developer of identity verification solutions, as one of the top-performing companies in the Identity Verification category, based on customer feedback in the Spring 2026 report. Users gave Regula a Net Promoter Score (NPS) of...

Read moreDetails

Skyworks Introduces Si86Px Digital Isolators with Integrated Power for Space‑Constrained Industrial Designs

IRVINE, Calif., April 28, 2026 (GLOBE NEWSWIRE) -- Skyworks today announced the Si86Px family of digital isolators with integrated power, a compact solution that combines high‑performance digital isolation with an integrated isolated dc‑dc converter and matched miniature transformer. Designed for industrial and automotive electronics, the Si86Px simplifies isolated system design...

Read moreDetails

AI Networking Innovator Eino Launches its Agentic Network Observability Platform

NEW YORK, April 28, 2026 (GLOBE NEWSWIRE) -- Eino, an innovator in AI-native network planning, design, and monitoring for enterprise networks, today introduced a new class of solution for enterprises known as Agentic Network Observability. Designed for enterprises with multiple network technologies and mission-critical use cases, Eino’s agentic solution uses...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Understanding Soulbound Tokens SBT Their Definition and Significance

    53 shares
    Share 21 Tweet 13
  • Discover 2025’s Top 5 Promising Low-Cap Crypto Gems

    98 shares
    Share 39 Tweet 25
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    159 shares
    Share 64 Tweet 40
  • 74Software completes refinancing of its Term Loans and Revolving Credit Facility

    5 shares
    Share 2 Tweet 1
  • Top Cross-Chain DeFi Solutions to Watch by 2025

    86 shares
    Share 34 Tweet 22
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Peer To Peer Network (OTC:PTOP) Announces MOBICARD(TM) Development Accelerates Ahead of Schedule as Company Expands Enterprise Features, Discovery Mode and Industry-First Audio Analytics
  • Predictiv AI’s Shift Technologies Enters Strategic Joint Venture with Arcasia Holdings (Pvt) Ltd. to Deploy AI-Powered Logistics Platform Across Global First, Middle, and Last Mile Networks
  • CSPi Technology Solutions Announces New Partnership with Juniper Landscaping for Vital(TM) Managed IT Services
  • InHand Introduces POS Ready to Prioritize POS Transactions During Peak Network Usage
  • Quokka Research Finds Widespread Mobile App Security Failures Across Android and iOS

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.