Monday , August 3 2026
NGate
Screens that ask the victim to place their bank card on the back of their smartphone | Source: Doctor Web

New NGate Trojan Drains Bank Accounts via ATMs

Malware analysts at Doctor Web have identified new versions of the NGate banking trojan. This malware steals data from the device’s NFC chip, enabling attackers to withdraw money from victims’ accounts at ATMs without their knowledge.

The NGate banker was first noticed by antivirus vendors in autumn 2023 due to attacks on major Czech banks. The attackers used social engineering, phishing, and malware to gain remote access to victims’ payment NFC capabilities. While Czech law enforcement managed to halt this campaign, the method was later adapted for illegal use in Russia.

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

Fraudsters often start their attack with a phone call, claiming the victim is eligible for social benefits or financial gain. To receive it, the victim is instructed to click a link that leads to a fake website. This site hosts a malicious APK disguised as an app for the Gosuslugi portal, the Bank of Russia, or other popular banks, containing the NGate trojan.

The NGate banking trojan is a malicious version of the open-source NFCGate app, originally designed for debugging NFC data transfers. Attackers exploit its ability to capture NFC traffic and send it to a remote device, like a server or their own phone. They’ve altered the code to include a user interface resembling official apps and activated NFC data relay. Additionally, the app incorporates the nfc-card-reader library, allowing hackers to remotely access card numbers and expiry dates.

Once the user opens the fake application, they are asked to place their payment card on the back of the smartphone, enter their PIN, and wait for verification. During this process, all card information is collected and sent to the criminals. No rooting of the smartphone is required to access NFC data.

The attacker can steal a victim’s bank card information by holding their smartphone near the victim’s card while requesting cash from an ATM or making a contactless payment. The hacker taps their phone to transmit the victim’s card details, using the PIN the victim previously entered to confirm the transaction.

To prevent money theft, “Doctor Web” analysts recommend:

do not share your PIN or CVV codes for your bank cards,
use an antivirus program, it will block downloading and installation of malicious applications,
carefully check the addresses of web pages that ask for financial information,
only install applications from official sources such as AppGallery and Google Play,
do not talk to scammers. If you receive an unexpected call from the police, a bank or any other organization, simply hang up. If you have any doubts about the legitimacy of the call, find the contact details on the official website and contact the organization yourself.

Check Also

Marquis

Over 74 US banks, credit unions impacted via Marquis data breach

Marquis Software Solutions has announced a data breach affecting multiple banks and credit unions in …