Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →The threat is real, but it is not a universal contactless-card cloning attack. The main campaigns require a victim to install a malicious Android app—often after a convincing bank-support or payment message—and then tap a physical payment card against the infected phone. The malware relays that live NFC exchange to an attacker-controlled device, which may attempt a purchase or cash withdrawal.
Zimperium reported more than 760 malicious Android apps and over 70 command-and-control servers or distribution hubs in activity concentrated in Eastern Europe. Those are researcher-observed samples, not a confirmed count of victims or successful fraud. The technique has continued evolving, with later families including RatOn and PhantomCard.
What happened
Coverage published on October 30, 2025 described a large collection of Android malware abusing NFC (near-field communication) and Android’s Host Card Emulation capability. According to BleepingComputer’s report, Zimperium observed more than 760 malicious apps, more than 70 command-and-control servers or distribution hubs, and Telegram channels or bots linked to the campaigns. Fake apps impersonated Google Pay and banks including Santander, VTB, Tinkoff, ING, Bradesco and Promsvyazbank.
The reporting emphasized Russia, Poland, the Czech Republic, Slovakia and other Eastern European markets. It did not establish that every European cardholder was targeted, that all 760-plus apps were used successfully, or that the entire European payments system was compromised. ESET later reported an 87% increase in NFC-threat detections in its own telemetry during the second half of 2025, showing continued growth but not measuring every attack worldwide.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- STYLISHLY SMALL, SLIM & DISCREET: Measuring just 3 1/8" x 4 7/16", our RFID front pocket wallet is designed to be super thin and exceptionally slim. Its modern, minimalist profile fits perfectly in your pocket, purse, or travel pack without adding bulk.
- SURPRISINGLY SPACIOUS: Though slim, it features 8 slots to easily organize your essentials. Comfortably holds your driver's license, credit cards, debit cards, and membership cards, keeping everything you need right at your fingertips.
- ADVANCED RFID BLOCKING: Our slim wallets for men and women are outfitted with advanced RFID SECURE Technology. They block electronic signals to keep your identity protected while you travel, shop, or explore, safeguarding you from digital theft.
- DURABLE & STYLISH FAUX LEATHER: Crafted from premium synthetic leather, this minimalist wallet sleeve combines a luxurious look and feel with everyday functionality. Its durable construction is designed to withstand the rigors of daily use, travel, and shopping.
- THE PERFECT UNISEX GIFT: With its sleek design and practical security features, this wallet is a popular choice for both men and women. It arrives ready for gifting, making it an ideal present for the frequent traveler, minimalist, or anyone in your life!
By August 2026, the original app count should be treated as a dated observation rather than a complete current total. Newer campaigns demonstrate that NFC relay is an expanding technique, not one isolated operation.
How NFC relay malware works
NFC is the short-range radio technology used by contactless cards, phones and payment terminals. Host Card Emulation lets Android software act like a card to an NFC reader. In a relay attack, malware does not normally create a permanent duplicate of the victim’s card. It forwards messages between the real card and a remote reader while the transaction is happening.
Rank #2
- Slim and Thin Wallet - This minimalist bifold wallet measures 4.3x3.2x0.6 inches and stores up to 15 cards. The bifold wallet perfectly fits in your pocket and is well-suited for everyday carry
- Elite Features - 2 ID windows (DL & Other ID Cards) and 2 quick slots allow for quick access during travel, shopping or work. With 15 card slots and 2 more slots behind them, it is easy to carry all your important cards,cash and bills, meet all your daily needs
- RFID Blocking- Our wallets are equipped with advanced RFID SECURE Technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals and protect the valuable information stored on RFID chips from unauthorized scans.License and ID cards will be protected effectively. No more worrying about unauthorized scans during travel, shopping, or daily commuting!
- Durable Surface - Our leather wallets are pressed with high quality 3 layers leather, which is more durable than 2 layers leather wallets. The surface of the leather is made more scratch-resistant by special treatment, which can effectively prevent small scratches caused by keys and buttons in life
- Gifts for him - The thin wallet comes in classy gift packaging. It is a perfect present for birthdays, anniversaries, Father's Day, Valentine's Day, Christmas and other special occasions, so you can easily gift it to someone you love
- Social engineering starts the chain. A victim receives a text, call, advertisement or phishing link pretending to be a bank, payment provider or government service.
- A fake app is installed. The victim may be directed to an APK outside Google Play, although official-store availability is not proof that every sample was sideloaded.
- Powerful permissions are requested. Depending on the family, the app may seek NFC, accessibility, notification, SMS, overlay, device-administration or foreground-service access.
- The victim taps a physical card. The instruction may be described as verification, activation, a refund, an NFC repair or security testing. This victim-initiated tap is normally essential.
- NFC communication is captured or relayed. Card-to-phone messages, including application protocol data units (APDUs), are sent through command-and-control infrastructure.
- An attacker attempts a transaction. A second device near a point-of-sale terminal or ATM presents the relayed exchange. Approval depends on timing, terminal and issuer controls, card rules and any required verification.
A criminal generally cannot obtain a complete usable card credential simply by standing next to someone in a queue. The specific chain described here requires a compromised Android phone and a card tap.
The malware families are related, not identical
| Family or campaign | What researchers reported | Geography and timing |
|---|---|---|
| NGate | One of the first publicly documented Android NFC-relay threats; used relaying to support unauthorized ATM withdrawals. | Publicly documented by ESET in 2024. |
| SuperCard X | Captured payment-card NFC data and relayed it in real time. INCIBE described encrypted HTTP/TLS communications and use against point-of-sale terminals and ATMs. | Italian campaign reported in April 2025; Italy was the campaign location, not proof of exclusive impact. |
| Zimperium’s 760-plus-app activity | More than 760 malicious Android apps, over 70 servers or distribution hubs, and impersonation of banks and Google Pay. The figure reflects observed samples, not confirmed victims or losses. | Reported October 30, 2025; concentrated in Eastern Europe. |
| RatOn | ESET described NFC relay combined with remote-access-trojan functionality, giving operators capabilities beyond card communication. | Reported in ESET’s H2 2025 threat reporting. |
| PhantomCard | ESET described an NGate-based campaign adapted for Brazilian victims. | Observed in Brazil; this does not show that the original Eastern European app campaign spread there. |
Technical details differ among data harvesters, APDU-forwarding tools, HCE emulators and remote-access malware. Treating every sample as the same program obscures how the criminals adapt.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRank #3
- Ultra-thin: This wallet measures 4.3 x 3 x 0.5 inches and can hold at least 11 cards and 15-20 bills. Even when it's packed full, it's only 0.8 inches thick,It can perfectly conceal itself in your pocket without any noticeable bulge.
- Rfid Blocking: Our wallets are equipped with German Instiute Certified RFID Security technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals to protect the valuable information and privac.
- Lifetime After-sales Service: Regardless of the circumstances, if any GSOIAX brand wallet has a quality issue during your use, we promise to provide a full, unconditional, refund within 24 hours!
- Durable Surface: Crafted from premium 3-layer leather, our wallets outperform 2-layer alternatives in durability. Specially treated leather exterior delivers enhanced scratch resistance to guard against minor scuffs from everyday items like keys and buttons.
- Perfect Gifts For Him: This Money Clips Wallets for men comes in classy gift box package. It's a good idea to send the mens wallets as the gifts in birthday,anniversaries, Fathers Day,Valentine's Day,Christmas and other special occasions to someone you love.
Can the malware clone a contactless card?
Usually not in the simple, reusable sense implied by “clone.” EMV contactless payments use transaction-specific data and cryptographic authentication. A captured exchange does not automatically become a universally reusable physical-card copy. A relay attack instead tries to keep the legitimate card interaction alive long enough for a remote terminal to complete one transaction.
Success can depend on:
- latency and whether the terminal accepts the relayed exchange;
- the card’s EMV implementation and the terminal’s transaction rules;
- issuer risk controls and online authorization;
- whether a PIN or another verification step is required;
- contactless, ATM and transaction-value limits; and
- the attacker’s ability to place a second device near a compatible terminal.
EMV cryptography therefore does not make relay attacks impossible, but the attack does not defeat it by producing a magic copy of every card. Contactless limits may reduce losses in some markets, yet rules differ by country, issuer, terminal and transaction type.
Rank #4
- 【RFID Blocking Wallet for Men】Protect your personal information with our advanced RFID blocking tech. The wallet features a durable metal shell and composite materials that block 13.56 MHz and higher RFID signals, keeping your credit cards and IDs safe from electronic theft no matter where you are
- 【Card Slides Out Smoothly】This minimalist wallet features a button-activated ejection mechanism that pops cards up for easy access. The inner-facing slot ensures cards stay secure and never fall out
- 【Minimalist, Perfectly Slim】Designed to be sleek and easy to carry, featuring a dedicated ID card slot that allows for swiping without removing the card. It's perfect for ID cards, work badges, access cards, and transit cards. A separate cash compartment keeps your bills organized
- 【12 Card Slots & Cash Slot】Offers a total capacity of 12 cards (6 cards fitting in the chamber, 1 ID card, 4 slots on the wallet's outer surface, 1 slot on the card case exterior) and a cash slot. It features premium leather and aluminum chamber with a smooth pop-up card function, secured by a magnetic cover
- 【Premium Craftsmanship】Discover the perfect blend of quality and functionality with our wallet. Crafted from premium leather and airplane-grade aluminum, it features a convenient side pop-up for easy access. Durable and stylish, it complements both business and casual settings
Who is most exposed?
Risk is highest when several conditions overlap:
- the person uses Android;
- an untrusted or impersonating app is installed;
- the app receives NFC or powerful device permissions;
- the victim taps a physical card against that phone;
- the attacker can relay quickly to a compatible terminal or ATM; and
- issuer and terminal controls approve the resulting card-present transaction.
Removing any one condition can stop this particular chain, although it will not prevent unrelated credential theft or banking scams.
Physical cards are a different threat model from mobile wallets
The reported campaigns center on malicious Android apps and a physical payment card. They should not be confused with ordinary Google Wallet or Apple Pay use, where tokenized credentials and device authentication follow a different model. Android users can still be tricked by fake wallet or banking apps, and iPhone users can still lose credentials, one-time codes or money through social engineering. Neither platform should be described as immune to all NFC-related fraud.
Recommended Free Tools
Best Value
- ★REAL LEATHER: This wallet is MADE IN INDIA and comes in 2 leather qualities, namely Nappa and Crazy Horse. Nappa leather is conventional drum dyed leather which is finished with natural pigments to attain a smooth and buttery touch, while Crazy Horse is vegetable tanned and sprayed with oils and waxes to give a distressed look with warm and soft touch.
- ★ELITE FEATURES: ID windows allow for quick access when traveling or at the store /working place. With 5 card slots and 2 more slots behind them, it’s easy to carry all your important cards, meet all your daily needs.
- ★RFID BLOCKING ANTI THEFT SECURITY: Our wallets are anti theft, equipped with advanced RFID SECURE Technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals and protect the valuable information stored on RFID chips from unauthorised scans and make them anti theft.
- ★COMPACT DESIGN: Making this bifold superb for travel, and everyday use, keeping cards safe and organized! It holds 8+ cards, and lots of cash!
- ★GIFT BOX PACKING: It is one of the most special gifts for Groomsmen, Birthdays, Anniversaries, Father's Day, Christmas and other Special Occasions.
Warning signs to stop immediately
- An APK link delivered by SMS, WhatsApp, Telegram, email or an unsolicited support call.
- A caller claiming to be your bank who asks you to “verify” or “activate” a card by tapping it to your phone.
- Requests for accessibility, notification, SMS, overlay, device-administrator or unusual NFC permissions from a banking or wallet impersonator.
- Fake Google Pay or bank branding, especially when the installation path is not the bank’s official website or the app’s verified Google Play listing.
- An unexpected PIN prompt or transaction alert after you followed an NFC instruction. Stop and contact the bank rather than trying again.
What Android users should do now
If you have not installed anything
- Install banking and wallet apps only from the bank’s official website or the official Google Play listing.
- Keep Android and Google Play system updates current.
- Leave Google Play Protect enabled and review its warnings. Google’s Play Protect guidance explains the built-in service.
- Never tap a physical card against an unknown phone for verification, activation, refunds or “NFC repair.”
If you installed a suspicious app but did not tap a card
- Preserve the app name, message, phone number and screenshots if doing so is safe.
- Revoke its permissions, then uninstall it.
- Run Play Protect and update the device.
- From a clean device, change banking credentials if the app had accessibility, SMS, notification or screen-reading access.
- Contact the bank if you entered card or account information, and monitor transactions and new payees.
If you tapped a card against the phone
- Freeze the card immediately through the bank’s official app or the number printed on the card.
- Ask whether the issuer recommends replacement and whether contactless or ATM transactions can be blocked temporarily.
- Review pending and completed transactions.
- Report the malicious app and preserve messages, screenshots and phone numbers.
- Use a clean device for password changes and account recovery.
If a payment or cash withdrawal succeeded
- Report it immediately and obtain a case number.
- Ask about the issuer’s unauthorized-transaction, card-fraud or chargeback process; liability and reimbursement rules vary by country and card type.
- Report the incident to the relevant national cybercrime or police service.
- Do not factory-reset before collecting evidence if the bank or law enforcement requests it. Otherwise, prioritize securing accounts and removing the infection.
Temporarily disabling NFC can reduce exposure to the NFC component, particularly after suspected infection, but it does not disinfect the phone, reverse stolen credentials or stop remote-access malware.
What banks and payment providers should do
- Correlate transaction timing, location, terminal identity and cardholder history to flag unusual card-present activity after suspicious device interactions.
- Apply extra risk checks to rapid ATM or point-of-sale use following an unusual authorization pattern.
- Detect suspicious HCE behavior, malicious default payment handlers and compromised-device signals where possible.
- Tell customers clearly that legitimate staff will not ask them to tap a physical card against an unknown phone.
- Provide rapid card-freeze, replacement and dispute workflows.
- Coordinate with banks, card schemes, mobile platforms, telecom operators and law enforcement.
The objective is not to claim that relay malware breaks EMV cryptography. It is to detect abuse of a legitimate live transaction flow combined with social engineering.
Timeline and current limits of the evidence
| Date | Development |
|---|---|
| 2023 | Early NFC-relay activity was reported in Poland, according to the 2025 coverage. |
| 2024 | ESET publicly documented NGate. |
| April 2025 | INCIBE reported SuperCard X in an Italian campaign. |
| October 30, 2025 | Reporting described Zimperium’s 760-plus malicious-app observation and associated infrastructure. |
| December 2025 | ESET reported an 87% rise in its NFC-threat detections in H2 2025 and discussed RatOn and PhantomCard. |
| August 18, 2026 | The 2025 figures remain useful context, but they are not a complete current census of apps, victims or losses. |
Established facts include the documented malware families, observed samples, distribution tactics and reported regions. The sources do not establish the total number of victims, total financial losses, the share of apps that completed fraud, or whether every package shared code or infrastructure.
Quick Recap
Further reading
- INCIBE-CERT: SuperCard X Android malware uses NFC to steal credit cards
- ESET Threat Report, H2 2025
- Zimperium: SuperCardX NFC relay fraud operation
- Broadcom security bulletin on SuperCard X
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.




