Monday, April 27, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

ESET Research: New NGate hides in NFC payment app, possibly built with AI

April 21, 2026
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 6 mins read
5
SHARES
246
VIEWS
Share on TwitterShare on LinkedInShare on Facebook
  • ESET researchers discovered a new NGate malware variant abusing the legitimate Android HandyPay application.
  • To trojanize HandyPay, threat actors most likely used GenAI.
  • The campaign has been ongoing since November 2025 and targets Android users in Brazil.
  • ESET investigated two NGate samples being distributed in the attacks: one via a fake lottery website, the other through a fake Google Play website.

BRATISLAVA, Slovakia, April 21, 2026 (GLOBE NEWSWIRE) — ESET Research has discovered a new variant of the NGate malware family that abuses a legitimate Android application called HandyPay, instead of the previously leveraged NFCGate tool. The threat actors took the app, which is used to relay NFC data, and patched it with malicious code that appears to have been AI generated. As with previous iterations of NGate, the malicious code allows the attackers to transfer NFC data from the victim’s payment card to their own device and use them for contactless ATM cash-outs and unauthorized payments. Additionally, the code can capture the victims’ payment card PINs and exfiltrate them to the operators’ C&C server. The primary targets of this are users in Brazil; however, NFC-based attacks are expanding into new regions.

The malicious code used to trojanize HandyPay shows signs of having been produced with the help of GenAI tools. Specifically, the malware logs contain an emoji typical of AI-generated text, suggesting that LLMs were involved in generating or modifying the code, although definitive proof remains elusive. This fits a broader trend in which GenAI lowers the barrier to entry for cybercriminals, enabling threat actors with limited technical skill to produce workable malware.

ESET Research believes that the campaign distributing the trojanized HandyPay began around November 2025 and remains active. It should also be noted that the maliciously patched version of HandyPay has never been available on the official Google Play store. As an App Defense Alliance partner, we shared our findings with Google. ESET also reached out to the HandyPay developers to alert them about the malicious use of their application.

As the number of NFC threats keeps rising, so too has the ecosystem supporting them become more robust. The first NGate attacks employed the open-source NFCGate tool to facilitate the transfer of NFC data. Since then, several malware-as-a-service (MaaS) offerings with similar functionality have become available for purchase. However, in this campaign the threat actors decided to go with their own solution and maliciously patched an existing app – HandyPay.

“Why did the operators of this campaign decide to trojanize the HandyPay app instead of going with an established solution for relaying NFC data? The answer is simple: money. The subscription fees for existing MaaS kits run in the hundreds of dollars: NFU Pay advertises its product for almost US$400 per month, while TX-NFC goes for around US$500 per month. On the other hand, the legitimate HandyPay app is significantly cheaper, only asking for a €9.99 per month donation, if even that. In addition to the price, HandyPay natively does not require any permissions, only to be made the default payment app, helping the threat actors avoid raising suspicion,” says ESET researcher Lukáš Štefanko, who discovered the new NGate variant in the trojanized NFC payment app.

The first new NGate sample is distributed through a website that impersonates Rio de Prêmios, a lottery run by the Rio de Janeiro state lottery organization (Loterj). The second NGate sample is distributed via a fake Google Play web page as an app named Proteção Cartão (machine translation: Card Protection). Both sites were hosted on the same domain, strongly implying a single threat actor. The malware abuses the HandyPay service to forward NFC card data to an attacker-controlled device. Apart from relaying NFC data, the malicious code also steals payment card PINs, enabling the threat actor to use the victim’s payment card data to withdraw cash from ATMs.

For a more detailed analysis of the new NGate variant, check out the latest ESET Research blog post, “New NGate variant hides in a trojanized NFC payment app,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), Bluesky, and Mastodon for the latest news from ESET Research.

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown — securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit http://www.eset.com or follow our social media, podcasts and blogs.

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.

ShareTweet1ShareSendShare2
Previous Post

ESET Research: New NGate hides in NFC payment app, possibly built with AI

Next Post

Digital Empowerment for Traditional TCM – Laozhongyi and CUBE Platform Forge Strategic Partnership to Expand into Southeast Asia and the Middle East

Related Posts

AI Search Engineers Documents How Law Firms and Financial Advisors Are Winning AI-Generated Recommendations on ChatGPT and Google Gemini

Verified client outcomes across eight professional service engagements reveal the specific authority signals that determine which businesses get recommended by AI platforms, and which remain invisible AMHERST, NY / ACCESS Newswire / April 27, 2026 / AI Search Engineers, the only AEO Verified agency in the United States under the...

Read moreDetails

All Things Mobile Analytic, Inc. (OTC Pink: ATMH) Announces the Acquisition of NS12 S.p.A.

NEW YORK CITY, NY / ACCESS Newswire / April 27, 2026 / All Things Mobile Analytic, Inc. (OTCID:ATMH), a diversified technology company focused on fintech, global telecommunications, AI, data analytics, enterprise software and digital health solutions, is pleased to announce the signing of a definitive agreement to acquire NS12 S.p.A.,...

Read moreDetails

ROI Training Wins 2026 Google Cloud Global Training Partner of the Year Award

ROI Training announced that it has received the 2026 Google CloudGlobal Training Partner of the Year Award. NEW YORK CITY, NY / ACCESS Newswire / April 27, 2026 / ROI Training is being recognized for the company's achievements in the Google Cloud ecosystem, helping joint customers and partners successfully accelerate...

Read moreDetails

SkyTech Orion Global Corp. (CTGL) Announced Today the Release of an Updated Corporate Presentation

New York, April 27, 2026 (GLOBE NEWSWIRE) -- SkyTech Orion Global Corp. (CTGL), builder of end-to-end drone solutions, from innovative modular platforms to large-scale mass production and innovation centers, released today an updated corporate presentation accompanied by a letter to shareholders, as follows: Dear Shareholders and Partners, Since our last...

Read moreDetails

Goodman Group Announces Pricing of Cash Tender Offer for its 3.700% Guaranteed Senior Notes due 2028

SYDNEY, April 27, 2026 (GLOBE NEWSWIRE) -- Goodman Group (ASX: GMG) (“Goodman Group”) today announced the pricing of the previously announced cash tender offer (the “Offer”) by Goodman US Finance Three, LLC, a Delaware limited liability company (“Goodman”), to purchase any and all of its outstanding 3.700% Guaranteed Senior Notes...

Read moreDetails

Glass Launches the First Cooperative Purchasing Marketplace for AI Solutions in Partnership with Sourcewell

SAN FRANCISCO, April 27, 2026 (GLOBE NEWSWIRE) -- Glass, the Silicon Valley GovTech company transforming how governments buy and pay, today announced the launch of the G-Commerce AI Solutions Marketplace in partnership with Sourcewell—the first cooperative purchasing marketplace designed to help government agencies procure AI solutions with speed, simplicity, and...

Read moreDetails

TechEx North America 2026 Comes to San Jose For Your Annual Enterprise Technology Intelligence Briefing

San Jose, California , April 27, 2026 (GLOBE NEWSWIRE) -- TechEx North America will take place on May 18–19, 2026, at the San Jose McEnery Convention Center, bringing together seven co-located enterprise technology events under one roof to tackle the real questions enterprise leaders are asking right now. This leading...

Read moreDetails

Vmake Launches Advanced AI People Remover Mode to Clean Up Videos and Photos in One Click

SYDNEY, April 27, 2026 (GLOBE NEWSWIRE) -- Vmake, the all-in-one AI video creation platform, has announced the launch of its advanced AI People Remover mode that lets creators, marketers, and e-commerce professionals automatically remove unwanted people from videos and photos in ONE CLICK. The tool supports both images and videos....

Read moreDetails

Prodigii Licenses VERSES® Technology

VANCOUVER, British Columbia, April 27, 2026 (GLOBE NEWSWIRE) -- VERSES AI Inc. (CBOE:VERS) (OTCQB: VRSSF) ("VERSES'' or the "Company”), a cognitive computing company specializing in next-generation agentic software systems, today announced an additional expansion and extension of its relationship with Prodigii AI, LLC (“Prodigii”), an enterprise AI infrastructure company focused on...

Read moreDetails

CAQH Appoints Dr. Alex Ding as Chief Medical Officer

WASHINGTON, April 27, 2026 (GLOBE NEWSWIRE) -- CAQH, the trusted data connector at the core of healthcare, today announced that Alexander Ding, M.D., M.S., M.B.A., has joined the organization as Chief Medical Officer. In this role, Ding will bring a critical clinical perspective to CAQH’s strategy and solutions as the...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • FlipHTML5’s Flipbook Maker Creates Interactive Digital Publications Easily

    8 shares
    Share 3 Tweet 2
  • Understanding Soulbound Tokens SBT Their Definition and Significance

    53 shares
    Share 21 Tweet 13
  • Discover 2025’s Top 5 Promising Low-Cap Crypto Gems

    98 shares
    Share 39 Tweet 25
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    159 shares
    Share 64 Tweet 40
  • The HUB @ Office Logic Introduces Structured Deal Flow Access, Investor Readiness Engine, and Accelerator Program at Startup OLÉ Miami 2026

    5 shares
    Share 2 Tweet 1
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • OurFamilyWizard Expands International Reach with Launch in France and Spain
  • AI Search Engineers Documents How Law Firms and Financial Advisors Are Winning AI-Generated Recommendations on ChatGPT and Google Gemini
  • All Things Mobile Analytic, Inc. (OTC Pink: ATMH) Announces the Acquisition of NS12 S.p.A.
  • ROI Training Wins 2026 Google Cloud Global Training Partner of the Year Award
  • DDC Executive Vice President Named Dayton Business Journal Aerospace & Defense Awards Honoree

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.