Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New NFCShare Malware Targets Android Banking Apps

New NFCShare Malware Targets Android Banking Apps

Posted on June 9, 2026 By CWS

A sophisticated variant of Android malware, named NFCShare, is posing a significant threat to mobile users across Europe by masquerading as legitimate banking applications. This malware is engineered to covertly extract payment card data using the NFC chip embedded in smartphones, marking an expansion from its initial appearance.

Evolution and Expansion of NFCShare

Initially detected in January 2026, NFCShare first emerged by imitating Deutsche Bank’s app. It employs a deceptive card-verification screen, prompting users to place their payment card near the device, thereby capturing sensitive card data and transmitting it to a server controlled by attackers. Notably, the malware also records the card’s PIN before the victim becomes aware of the breach.

Security experts at d3Lab have monitored the malware’s progression, observing a marked escalation from mid-May 2026. The campaign has since broadened to mimic various Italian and European banking brands, including Intesa Sanpaolo, Banca Sella, and others, extending its reach to Spanish banks like CaixaBank.

Phishing Tactics and Distribution Channels

d3Lab’s report, shared with Cyber Security News (CSN), highlights the persistence of the core attack method but notes a refinement in execution. The cybercriminals frequently change the banking brands they impersonate, rapidly recreating malicious APKs and distributing them via a GitHub repository disguised as an educational project, complicating detection efforts.

Victims are directed to phishing websites, which closely resemble legitimate banking portals. After entering their credentials, users are misled into downloading a counterfeit APK under the guise of a necessary app update. In some cases, attackers further deceive victims through fake communication, instructing them to enable installations from unknown sources.

Technical Insights and Security Recommendations

The fake APKs bear names that mimic genuine banking apps, such as Intesa Carte.apk and CaixaBank.apk. Upon installation, the malware presents a standard-looking card-verification interface, leveraging Android’s NFC reader to execute EMV protocol commands and siphon card information, which is then relayed to the attackers’ command-and-control server.

One significant shift in the campaign is the utilization of GitHub as a delivery platform. The repository is masked as a school project with a misleading README file, and updates are pushed with messages in Italian. Moreover, new APK versions incorporate tactics to thwart security analysis, such as using malformed ZIP paths to disrupt simple detection tools.

For cybersecurity defenders, the key to identifying NFCShare lies in examining the internal code markers, the interplay of WebView and NFC functions, and the unique structure of the APK files. Tools like apkInspector, capable of handling non-standard ZIP formats, are recommended for effective detection and analysis.

This ongoing threat underscores the importance of vigilance and the need for robust security measures to protect against evolving mobile threats. As the campaign continues to adapt, staying informed and employing advanced security tools are crucial for safeguarding sensitive data.

Cyber Security News Tags:Android malware, banking apps, cyber threat, Cybersecurity, d3Lab analysis, data theft, European banks, fake apps, GitHub payloads, malicious APKs, mobile security, NFC chip, NFCShare, Phishing, security alert

Post navigation

Previous Post: Cryptographic Invisibility Revolutionizes AI App Security
Next Post: Critical Chrome Vulnerability CVE-2026-11645 Actively Exploited

Related Posts

CISA Releases Guidance for Managing UEFI Secure Boot on Enterprise Devices CISA Releases Guidance for Managing UEFI Secure Boot on Enterprise Devices Cyber Security News
VMware Cloud Foundation 9.0 Released With Modern Workloads & AI Services VMware Cloud Foundation 9.0 Released With Modern Workloads & AI Services Cyber Security News
Telegram Exposes Real Users IP Addresses, Bypassing Proxies on Android and iOS in 1-click Telegram Exposes Real Users IP Addresses, Bypassing Proxies on Android and iOS in 1-click Cyber Security News
As Third-Party Vulnerabilities Rise, CISOs Accelerate Push for Security Modernization   As Third-Party Vulnerabilities Rise, CISOs Accelerate Push for Security Modernization   Cyber Security News
Emerging Nexcorium Botnet Exploits DVR Vulnerability Emerging Nexcorium Botnet Exploits DVR Vulnerability Cyber Security News
Salty2FA and Tycoon2FA Phishing Kits Attacking Enterprise Users to Steal Login Credentials Salty2FA and Tycoon2FA Phishing Kits Attacking Enterprise Users to Steal Login Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Claude Mythos Revolutionizes Exploit Creation with AI
  • FROST Attack Exploits SSD Timing to Track Website Visits
  • AI’s Impact on the Future of Bug Bounties
  • Critical Chrome Vulnerability CVE-2026-11645 Actively Exploited
  • New NFCShare Malware Targets Android Banking Apps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Claude Mythos Revolutionizes Exploit Creation with AI
  • FROST Attack Exploits SSD Timing to Track Website Visits
  • AI’s Impact on the Future of Bug Bounties
  • Critical Chrome Vulnerability CVE-2026-11645 Actively Exploited
  • New NFCShare Malware Targets Android Banking Apps

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark