Researchers from Zimperium zLabs have uncovered a rapidly growing cybercrime trend involving Android applications that abuse NFC (Near Field Communication) and Host Card Emulation (HCE) to steal payment card data and conduct fraudulent βtap-to-payβ transactions.
What began as isolated incidents has now ballooned into over 760 malicious apps observed in the wild β an alarming sign that NFC relay abuse is accelerating, not slowing down.
Zimperiumβs investigation revealed that cybercriminals are expanding their operations beyond initial regions such as Russia, targeting victims across Poland, the Czech Republic, Slovakia, and Brazil. The company observed that βCampaigns previously documented by other vendors are now broadening their reach to additional regions.β
The researchers identified more than 70 command-and-control (C2) servers and dozens of Telegram bots and private channels used to exfiltrate stolen financial data and coordinate operations among criminal groups.
βApproximately 20 institutions have been impersonated β primarily Russian banks and financial services, but also organizations in Brazil, Poland, the Czech Republic, and Slovakia,β Zimperium reported.
The list of impersonated entities reads like a global banking directory. Among the targets are:
- Central Bank of Russia, VTB Bank, Promsvyazbank (PSB), and Tinkoff Bank (Russia)
- PKO Bank Polski (Poland)
- ΔeskoslovenskΓ‘ obchodnΓ banka (ΔSOB) (Czech Republic)
- National Bank of Slovakia (NBS) (Slovakia)
- Bradesco Bank and ItaΓΊ Bank (Brazil)
Even international services such as Google Pay and ING Bank were spoofed to increase credibility.
To lure victims, the fake apps masquerade as legitimate banking or government services, often using convincing icons, brand names, and web interfaces. Once installed, they prompt users to set the malicious app as the default NFC payment handler.
Behind the scenes, these apps exploit Androidβs NFC and HCE functionality to emulate a payment card, intercepting EMV (Europay, Mastercard, Visa) data fields directly from the device or card tap.
Zimperium explained: βThe applications are designed to require minimal user interaction, typically displaying a simple full-screen βbankβ pageβ¦ They prompt the user to set the app as the default NFC payment method, while background services silently handle NFC events.β

This approach allows attackers to relay NFC signals between the victimβs card and a fraudulent Point of Sale (POS) terminal elsewhere β effectively performing real-time βtap-to-payβ theft.
Within underground channels, threat actors refer to their victims as βMamontsβ β slang for βpreyβ or βtargetβ in Russian cybercriminal circles.
Some variants of the malicious apps act as βscanner/tapper toolsβ sold or distributed among threat actors, enabling card data extraction on one device and purchase execution on another.
Other variants focus purely on data collection, siphoning card numbers, expiration dates, and device IDs directly to private Telegram channels.
βThreat actors receive automated messages for each connected device, containing details such as device IDs, card numbers, expiration dates, and other EMV fields,β Zimperium said, accompanied by screenshots of real-time Telegram notifications.
Zimperiumβs telemetry revealed a complex command-and-control (C2) structure that coordinates communication between infected devices and attacker servers.
Each malicious app registers itself with a server, sending hardware identifiers, NFC capabilities, and geolocation data.
The C2 infrastructure supports a range of commands such as:
- register_device β Enrolls the infected phone in the attack network.
- apdu_command / apdu_response β Forwards or responds to payment terminal queries in real-time.
- get_pin / pin_response β Requests and transmits PIN data.
- update_required β Prompts victims to install βupdatesβ that are actually new malicious payloads.
This communication pattern allows cybercriminals to perform coordinated relay attacks, dynamically pairing compromised devices with POS systems during fraudulent transactions.
A recurring trend in this campaign is the heavy use of Telegram bots and channels for both data exfiltration and operator coordination.
Zimperium notes that βdozens of Telegram bots and private channels are being used by operators for exfiltration and coordination.β
These private channels automatically receive victim data in real time, often tagged by device ID or geographic region, streamlining the criminal workflow.
Zimperium concludes that NFC-based payment theft is becoming a mainstream cybercrime tactic, especially in regions with high adoption of contactless payments.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!