Cybersecurity researchers have identified a new Android malware campaign called PhantomCard that targets banking customers in Brazil through NFC relay fraud and call hijacking techniques. The malware enables unauthorized transactions by intercepting and relaying NFC data from victims’ payment cards to devices controlled by attackers, representing the latest evolution in a growing trend of NFC-based payment fraud.
The malware spreads through counterfeit Google Play web pages that impersonate legitimate card protection applications, including one named “Proteção Cartões” with package names “com.nfupay.s145” or “com.rc888.baxi.English”. These fake pages employ deceptive positive reviews to encourage app installation. Distribution likely occurs through social engineering methods such as SMS phishing, though the exact vector remains unconfirmed. The attack method matches recent campaigns like similar banking malware discovered in India.
Upon installation, the malware instructs users to place their credit or debit card against their phone’s back panel for supposed verification, displaying the message “Card Detected! Keep the card nearby until authentication is complete.” The process actually captures and transmits the card’s NFC data to the attackers’ relay server. Users are then prompted to enter their PIN, which is also sent to enable fraudulent transactions.
“PhantomCard relays NFC data from a victim’s banking card to the fraudster’s device… PhantomCard is based on Chinese-originating NFC relay malware-as-a-service,” reports cybersecurity firm ThreatFabric. The pattern matches Chinese cybercrime groups increasingly targeting mobile payment systems.
The malware exploits built-in NFC capabilities in modern Android devices to conduct relay attacks, where communication between legitimate cards and payment terminals is intercepted and relayed remotely to authorize transactions. The campaign also reportedly uses call hijacking techniques to intercept or manipulate phone calls, potentially circumventing two-factor authentication or social engineering defenses.
The campaign exemplifies broader security vulnerabilities in NFC-based contactless payment systems, particularly in regions with varying levels of digital infrastructure and security measures. Weaknesses including insufficient biometric authentication, inconsistent tokenization, and unencrypted NFC transactions increase fraud susceptibility. These gaps enable various attack methods including NFC skimming, card cloning, and relay attacks. The rise of such threats has led to increased adoption of enhanced authentication methods like biometrics and passkeys in payment systems.
Security experts emphasize that effective countermeasures include robust fraud detection systems, secure app distribution channels, and enhanced user awareness. The malware-as-a-service model employed by PhantomCard demonstrates how cybercriminals can now deploy sophisticated attacks with reduced technical barriers, a trend also seen in other recent Android banking malware campaigns.
Sources: The Hacker News, Frugal Testing, WeLiveSecurity