started · updated
Cybersecurity experts warn of new NFC-based banking fraud
Cybersecurity experts at Group-IB have issued a warning regarding a new fraud method that exploits Near Field Communication (NFC) technology to steal bank card data in real time. The attack typically begins with social engineering, where scammers pose as bank or utility employees via phone calls or messages to trick victims into installing malicious applications.
Once a device is compromised, attackers may use remote control tools like SpyNote to gain full access. Specialized malware can then exploit the phone's NFC capabilities to intercept and relay data between a victim's physical contactless card and the device. This data is forwarded to a separate device located elsewhere, allowing criminals to perform contactless transactions without ever physically possessing the victim's card.
Reports indicate that fake versions of popular apps, such as TikTok, have been used to distribute this tracking and data-stealing malware.