Image: Resecurity
Resecurity has uncovered a massive, evolving wave of fraud involving Near Field Communication (NFC) technology, exposing a growing threat driven by Chinese cybercriminal groups. With millions in damages reported by financial institutions, including a Fortune 100 bank in the U.S., this emerging threat is no longer fringeβitβs becoming a global crisis.
βNumerous banks, FinTechs, and credit unions have reported increased NFC-related fraud and highlighted significant challenges in early detection,β notes Resecurity.
NFC enables contactless payments, which surged during the COVID-19 pandemic. Today, more than 1.9 billion smartphones are NFC-enabled, making tap-and-go transactions seamless. But what was built for convenience has turned into a weapon for cybercriminals, who are using custom tools to emulate NFC cards and relay stolen data.
One standout technique is the βGhost Tapβ, where bad actors relay stolen credit card data through an NFC-enabled device to make unauthorized purchases at POS terminals:
βThe ‘Ghost Tap’ technique enables cybercriminals to cash out money from stolen credit cards linked to mobile payment services… without triggering traditional fraud detection.β
Tools like Track2NFC and Z-NFC have emerged as key players in these attacks. Track2NFC allows attackers to store stolen magnetic stripe data on phones and initiate NFC-based payments. Meanwhile, Z-NFCβa heavily obfuscated Android malwareβemulates NFC smart cards using Host Card Emulation (HCE) to hijack APDU commands.
βThe Z-NFC Card Emulatorβ¦ enables unauthorized access to contactless systems, including payment terminals and credit card infrastructure,β Resecurity reveals.
Reverse engineering shows Z-NFC utilizes encrypted native libraries (libjiagu.so, libjgdtc.so) and dynamic runtime injection to avoid static detection, functioning as both malware loader and NFC emulation engine.
Cybercriminals now sell NFC-enabled POS terminals on the Dark Web, many registered by money mules. Theyβre even offering e-SIMs, NFC readers, and “white plastic” cards to clone and use stolen payment data.
Loyalty programs are also under fire. Resecurity found fraudsters using tools like X-NFC to exploit airline miles, hotel points, and gas rewards, with Telegram channels offering video tutorials and support.
βX-NFC customers are widely using this approach to defraud consumers of airlines, hotels, gas (petro) loyalty programs and steal their points.β
Chinese cybercriminals focus on high-value economiesβU.S., UK, Australia, Saudi Arabia, and moreβexploiting weak CVM (Cardholder Verification Method) thresholds and security flaws in mobile wallet apps. Many of these groups appear to operate from within China and collaborate via closed Chinese-language Telegram groups, where some channels exceed 5,900 active members.
βChinese cybercriminals have become highly active in defrauding consumers worldwide by exploiting NFC technology and leveraging specialized toolsβ¦β
Beyond financial theft, the ability to emulate NFC ID systems creates alarming risks for access control, identity theft, and even infrastructure sabotage. NFC spoofing can compromise government buildings, healthcare networks, or enterprise systems, making it a national security issue.
βWithout decisive action, these cybercriminals will continue to exploit NFC technology, posing a serious risk to consumers and businesses worldwide,β the report concludes.
Related Posts:
- Apple Breaks the Mold: iPhone NFC Opens to Third-Party Payments
- “Ghost Tap” Emerges: Cybercriminals Exploit NFC Relay for Contactless Cash-Outs
- Ghost Plugin Plagues Over a Million Terminals, Hijacking Search Results and User Data
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.