Monday , August 24 2026
NGate
Screens that ask the victim to place their bank card on the back of their smartphone | Source: Doctor Web

New NGate Trojan Drains Bank Accounts via ATMs

Malware analysts at Doctor Web have identified new versions of the NGate banking trojan. This malware steals data from the device’s NFC chip, enabling attackers to withdraw money from victims’ accounts at ATMs without their knowledge.

The NGate banker was first noticed by antivirus vendors in autumn 2023 due to attacks on major Czech banks. The attackers used social engineering, phishing, and malware to gain remote access to victims’ payment NFC capabilities. While Czech law enforcement managed to halt this campaign, the method was later adapted for illegal use in Russia.

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

The Cl0p ransomware group has listed over 40 organizations that they say they targeted in a recent attack. This attack...
Read More
Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

Fraudsters often start their attack with a phone call, claiming the victim is eligible for social benefits or financial gain. To receive it, the victim is instructed to click a link that leads to a fake website. This site hosts a malicious APK disguised as an app for the Gosuslugi portal, the Bank of Russia, or other popular banks, containing the NGate trojan.

The NGate banking trojan is a malicious version of the open-source NFCGate app, originally designed for debugging NFC data transfers. Attackers exploit its ability to capture NFC traffic and send it to a remote device, like a server or their own phone. They’ve altered the code to include a user interface resembling official apps and activated NFC data relay. Additionally, the app incorporates the nfc-card-reader library, allowing hackers to remotely access card numbers and expiry dates.

Once the user opens the fake application, they are asked to place their payment card on the back of the smartphone, enter their PIN, and wait for verification. During this process, all card information is collected and sent to the criminals. No rooting of the smartphone is required to access NFC data.

The attacker can steal a victim’s bank card information by holding their smartphone near the victim’s card while requesting cash from an ATM or making a contactless payment. The hacker taps their phone to transmit the victim’s card details, using the PIN the victim previously entered to confirm the transaction.

To prevent money theft, “Doctor Web” analysts recommend:

do not share your PIN or CVV codes for your bank cards,
use an antivirus program, it will block downloading and installation of malicious applications,
carefully check the addresses of web pages that ask for financial information,
only install applications from official sources such as AppGallery and Google Play,
do not talk to scammers. If you receive an unexpected call from the police, a bank or any other organization, simply hang up. If you have any doubts about the legitimacy of the call, find the contact details on the official website and contact the organization yourself.

Check Also

Marquis

Over 74 US banks, credit unions impacted via Marquis data breach

Marquis Software Solutions has announced a data breach affecting multiple banks and credit unions in …