Malware, Threat Intelligence

NFC relay attack campaign ‘RelayNFC’ unveiled in Brazil

As reported by The Cyber Express, Cyble Research and Intelligence Labs have uncovered a new NFC relay attack campaign named "RelayNFC," targeting users in Brazil. A malicious app, distributed through phishing sites, claims to secure payment cards but instead captures victims' card details for fraudulent transactions.

The RelayNFC malware, described as lightweight and evasive, utilizes a Hermes-compiled payload with a JavaScript engine to stealthily capture and relay card data to attackers. The malware's undetectable nature poses a significant threat as it remains unseen by security tools, with zero VirusTotal detections. The attackers exploit a full real-time APDU relay channel to conduct transactions remotely, mimicking physical card presence.

The emergence of RelayNFC highlights a concerning trend in NFC exploits, with other malware strains like Ngate and SuperCardX also leveraging NFC capabilities for malicious activities. The reliance on phishing for distribution underscores the need for heightened user awareness and robust device-level protections. Financial institutions are urged to enhance monitoring practices to combat the evolving threat landscape posed by such sophisticated malware.

Source: The Cyber Express

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds