ESET Research has discovered a new variant of the NGate malware family that abuses a legitimate Android application called HandyPay, instead of the previously leveraged NFCGate tool. The threat actors took the app, which is used to relay NFC data, and patched it with malicious code that appears to have been AI-generated. As with previous iterations of NGate, the malicious code allows the attackers...
This report highlights the evolving tactics of cybercriminals leveraging AI and legitimate infrastructure to execute financial fraud. The strongest version of this narrative underscores the growing sophistication of NFC-based attacks, particularly in Brazil, where threat actors are combining social engineering with technical exploitation. The use of AI-generated code, while not definitively proven, aligns with broader trends of lowered barriers to entry for malware development. The attackers' ch...
