NFCShare Android Trojan: NFC card data theft via malicious APK
A new Android trojan, named NFCShare, has been discovered targeting Deutsche Bank customers through a phishing campaign. The malware, disguised as a banking app update, prompts users to perform a fake card verification process. It exploits NFC technology to steal card data and PINs, which are then exfiltrated to a remote WebSocket endpoint. The trojan's distribution, user flow, and technical analysis are detailed, including its NFC reading capabilities and string obfuscation techniques. The malware shows links to Chinese-linked tooling and similarities to other NFC-based threats. IOCs include hashes, package details, and network indicators.
Pulse ID: 697c693880e53e3f443b484c
Pulse Link: https://otx.alienvault.com/pulse/697c693880e53e3f443b484c
Pulse Author: AlienVault
Created: 2026-01-30 08:18:00
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Bank #Chinese #CyberSecurity #DataTheft #Endpoint #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Trojan #bot #AlienVault