NFCShare Android malware spreads via fake banking app updates on GitHub
Fake updates for trustworthy banking apps posted on GitHub are being used to spread new versions of the NFCShare Android virus.
The infection has developed into a phishing campaign that targets clients of several banks and financial institutions around Europe in an attempt to obtain credit card information.
NFCShare uses Android's IsoDep interface and EMV commands to read the data after deceiving victims with a phony verification page to place the cards close to the mobile device's near-field communication (NFC) chip.
Under the guise of a security precaution, the malware obtains the victim's card number, type, expiration date, and four-digit PIN. It then uses a WebSocket channel to exfiltrate the information to the attacker's command-and-control (C2) host read more about NFCShare...


