NFC attacks on Android phones surge 188 percent
Kaspersky said NFC-based attacks on Android smartphones targeting users’ funds rose by 188 percent in the first four months of 2026 from the same period in 2025, signaling a sharper cybercrime shift toward contactless payment fraud.
From January to April 2026, Kaspersky cybersecurity solutions blocked 35,600 attacks involving different Android malware families that use near-field communication techniques.
The attacks involved SuperCard X, PhantomCard, NGate, and other malicious modifications of the NFCGate tool.
The latest figure compared with more than 12,300 attacks blocked during the first four months of 2025.
Kaspersky said users in Russia face NFC relay mobile threats more often.
The cybersecurity company said users in other regions, especially Latin America and Europe, are also encountering NFC-based attacks.
Kaspersky said it had predicted at the end of 2025 that attacks on NFC payments would increase in 2026.
NFC, or near-field communication, enables short-range wireless communication used in contactless payments, transit systems, access cards, and other smartphone-based services.
Security researchers have long warned that NFC-based systems can be exposed to relay attacks, where attackers extend or manipulate a legitimate contactless transaction to make it appear valid.
Kaspersky said attackers are currently using two main NFC-based schemes.
The first scheme is direct NFC.
In direct NFC attacks, fraudsters contact victims through messaging apps and pretend to verify their identity.
Victims are then tricked into downloading malware disguised, for example, as a financial application.
The malware prompts victims to tap their bank card to an infected smartphone and enter the card PIN.
Kaspersky said this process hands over the card data to attackers.
The second scheme is reverse NFC.
In reverse NFC attacks, scammers send users a malicious application and use social engineering to persuade them to set the app as the primary contactless payment method on their compromised smartphones.
The malicious application generates an NFC signal that ATMs recognize as the scammers’ card.
Victims are then persuaded to go to an ATM and deposit funds into a supposed “secure account” using the infected phone.
Kaspersky said the money actually goes to the scammers.
“While previously attackers relied on ‘direct NFC’ scheme, now the ‘reverse NFC’ appears more common,” comments Sergey Golovanov, chief security expert at Kaspersky. “The danger of a newer, more sophisticated scheme is that this type of fraud is harder to detect and fight against, because victims themselves transfer money to the attackers’ accounts and such transactions are hard to distinguish from legitimate ones. We do not rule out that NFC relay malware itself continue to evolve and geography of attacks will expand. That’s why this threat should be further closely monitored.”
“The first publicly reported attacks that used a modified legitimate NFC tool occurred in late 2023. Those attacks were primarily detected in Europe. Then users from Russia and other regions faced similar mobile malware attacks. Later it became known that cybercriminals packaged NFC relay malware into malware-as-a-service (MaaS) offering, potentially simplifying access to malicious tools for other attackers. NFC relay campaigns demonstrate how threat actors adapt and reuse new methods to steal users’ funds,” added Dmitry Kalinin, cybersecurity expert at Kaspersky.
Kaspersky advised Android users to avoid installing apps from unofficial sources.
The company said users should be wary of links sent through messaging apps, social media, SMS, or recommendations made during phone calls.
Kaspersky also urged users never to follow instructions from strangers at an ATM, regardless of who they claim to be.
The company recommended using a comprehensive security solution on Android smartphones to prevent visits to phishing sites from web browsers and messengers and stop malware installation.
Kaspersky is a global cybersecurity and digital privacy company founded in 1997.
The company said it has protected more than a billion devices to date from emerging cyberthreats and targeted attacks.
Kaspersky said its threat intelligence and security expertise are used to develop solutions and services for individuals, businesses, critical infrastructure, and governments.
The company’s portfolio includes digital life protection for personal devices, specialized security products and services for companies, and Cyber Immune solutions for sophisticated and evolving digital threats.
Kaspersky said it helps millions of individuals and nearly 200,000 corporate clients protect what matters most to them.
Comments (0)
LEAVE A REPLY
No comments yet
Be the first to share your thoughts!
Related Articles

DOE, ERC back removal of system loss charges
MANILA — The Department of Energy and the Energy Regulatory Commission backed President Ferdinand R. Marcos Jr.’s call to remove system loss charges from electricity bills, while stressing that the proposed reform must preserve reliable service and the financial viability of power distributors. Removing the charge could reduce monthly expenses for households and operating costs


