Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New SuperCard Malware Using Hacked Android Phones to Relay Data from Users Payment Cards to Attackers Device

New SuperCard Malware Using Hacked Android Phones to Relay Data from Users Payment Cards to Attackers Device

Posted on June 18, 2025June 18, 2025 By CWS

In a regarding growth for cell fee safety, cybersecurity consultants have recognized a complicated new malware pressure named “SuperCard” that exploits Android units to steal fee card information.

This malicious software, a modified model of the reliable NFCGate program, intercepts Close to Area Communication (NFC) visitors throughout contactless funds, successfully turning compromised telephones into relay units that transmit delicate monetary data on to attackers.

First detected in April 2025 by Italian safety agency Cleafy, SuperCard initially focused European banking clients earlier than increasing its attain.

The malware operates as a part of a well-organized “malware-as-a-service” (MaaS) platform referred to as SuperCard X, which cybercriminals can subscribe to by means of underground Telegram channels.

In contrast to earlier NFC-exploiting threats, SuperCard presents subscribers subtle buyer help companies, reflecting the more and more skilled nature of right this moment’s cybercrime ecosystem.

Habr researchers recognized that the assault begins with social engineering techniques, the place victims obtain messages from seemingly reliable sources urging them to put in what seems to be a helpful software.

As soon as put in, the malware requests permissions to entry the machine’s NFC module and fee techniques, establishing itself because the default fee handler.

// Simplified illustration of SuperCard’s NFC interception mechanism
@Override
public void onTagDiscovered(Tag tag) {
IsoDep isoDep = IsoDep.get(tag);
strive {
isoDep.join();
byte[] command = {0x00, 0xA4, 0x04, 0x00, 0x07, 0xA0, 0x00, 0x00, 0x00, 0x42, 0x10, 0x10};
byte[] end result = isoDep.transceive(command);
// Intercept and ahead card information to C2 server
sendToAttacker(end result);
} catch (Exception e) {
Log.e(“SuperCard”, “Error speaking with card”, e);
}
}

An infection Mechanism and Knowledge Exfiltration

The sophistication of SuperCard lies in its multi-stage an infection course of. After set up, the malware stays dormant till it detects a fee transaction.

When a consumer makes an attempt to make a contactless fee, SuperCard prompts within the background, capturing the transaction information whereas permitting the reliable fee to proceed.

This stealth strategy ensures victims stay unaware of the compromise whereas their card particulars are transmitted to command-and-control servers.

F6 safety analysts report that SuperCard has already compromised over 175,000 Android units in Russia alone, with damages exceeding 432 million rubles within the first quarter of 2025.

The malware’s fast world unfold demonstrates the evolving menace panorama for cell fee techniques, requiring customers to train excessive warning when putting in purposes, even those who seem reliable.

Energy up early menace detection, escalation, and mitigation with ANY.RUN’s Risk Intelligence Lookup. Get 50 trial searches.

Cyber Security News Tags:Android, Attackers, Cards, Data, Device, Hacked, Malware, Payment, Phones, Relay, SuperCard, Users

Post navigation

Previous Post: 5 New Trends In Phishing Attacks On Businesses 
Next Post: Insecure GitHub Actions in Open Source Projects MITRE and Splunk Exposes Critical Vulnerabilities

Related Posts

North Korean Kimsuky and Lazarus Join Forces to Exploit Zero-Day Vulnerabilities Targeting Critical Sectors Worldwide North Korean Kimsuky and Lazarus Join Forces to Exploit Zero-Day Vulnerabilities Targeting Critical Sectors Worldwide Cyber Security News
Incident Response Planning – Preparing for Data Breaches Incident Response Planning – Preparing for Data Breaches Cyber Security News
How SOCs Detect More Threats without Alert Overload How SOCs Detect More Threats without Alert Overload Cyber Security News
Conducting Risk Assessments That Drive Business Value Conducting Risk Assessments That Drive Business Value Cyber Security News
PoC Exploit Released for Use-After-Free Vulnerability in Linux Kernel’s POSIX CPU Timers Implementation PoC Exploit Released for Use-After-Free Vulnerability in Linux Kernel’s POSIX CPU Timers Implementation Cyber Security News
Ubiquiti UniFi Protect Camera Vulnerability Allows Remote Code Execution Ubiquiti UniFi Protect Camera Vulnerability Allows Remote Code Execution Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Huskeys Secures $8 Million in Seed Funding for ESM Platform
  • Critical XSS Flaw in Jira Could Compromise Organizations
  • Russian Group Star Blizzard Utilizes DarkSword iOS Exploit
  • Secrets Sprawl Expands in 2026: Key Insights for CISOs
  • Urgent Patches Address Critical Grafana Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Huskeys Secures $8 Million in Seed Funding for ESM Platform
  • Critical XSS Flaw in Jira Could Compromise Organizations
  • Russian Group Star Blizzard Utilizes DarkSword iOS Exploit
  • Secrets Sprawl Expands in 2026: Key Insights for CISOs
  • Urgent Patches Address Critical Grafana Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark