Listen to this Post
In a disturbing development for mobile security, a new Android malware-as-a-service (MaaS) platform called SuperCard X has emerged, capable of conducting sophisticated near-field communication (NFC) relay attacks. This innovative threat is designed to compromise payment card data and conduct fraudulent cashouts. Cybercriminals are using this tool to target customers of banking institutions and card issuers, particularly in Italy. Cleafy, a fraud prevention firm, uncovered the platform and its methods, which involve a complex combination of social engineering, malicious app installation, and NFC data interception. As mobile banking becomes more integrated into our daily lives, such attacks could pose a serious financial risk.
Overview of the SuperCard X Malware Campaign
SuperCard X is the work of a Chinese-speaking threat actor group. This malware platform facilitates fraud by targeting banking customers through deceptive practices. The attackers rely on social engineering tactics to trick users into installing malicious applications on their Android devices. Once installed, these apps enable the malware to intercept NFC communications between users’ devices and point-of-sale (PoS) systems or ATMs.
Victims of this campaign are initially lured through fake security alerts sent via SMS or WhatsApp, which impersonate bank notifications about suspicious transactions. The messages create a false sense of urgency, urging victims to contact a provided phone number to resolve the issue. Once the victim calls, the attackers employ Telephone-Oriented Attack Delivery (TOAD) to convince them to install a malicious app under the guise of security software.
The malware then activates NFC relay functionality, capturing the victim’s payment card details by having them bring their card close to the infected device. This data is relayed to a threat actor-controlled server, enabling the attackers to perform fraudulent transactions. The malware works by having a companion app, known as Tapper, on the attacker’s device that receives the stolen card details.
The malware also manipulates victims into changing their security settings, such as removing card limits and sharing PINs, to facilitate easier withdrawals. Once the fraudsters have control over the stolen card data, they can use it to make unauthorized purchases or withdraw funds from ATMs.
What Undercode Say:
The SuperCard X campaign represents a frightening evolution in mobile banking fraud, blending social engineering, NFC relay attacks, and malware to bypass traditional security measures. The multi-stage approach, from fake security alerts to malicious app installation and NFC data interception, showcases a high level of sophistication. This not only makes it harder for regular users to detect but also forces security teams to rethink their detection and prevention strategies.
One of the key elements of the attack is the manipulation of NFC technology, which has become a standard feature in modern mobile payment systems. NFC allows devices to communicate wirelessly with point-of-sale terminals and ATMs. By intercepting and relaying this communication, attackers can perform fraudulent transactions without ever physically possessing the victim’s card.
SuperCard X’s reliance on a MaaS (Malware-as-a-Service) model is particularly worrying because it lowers the barrier to entry for cybercriminals. These attackers do not need advanced technical skills to carry out sophisticated fraud; they simply need access to the platform and its associated tools. This business model enables a broader range of threat actors to participate in financial fraud, making it a scalable and potentially long-lasting threat.
Moreover, the fact that attackers can manipulate users into changing card settings over phone calls is an alarming development. It underscores the vulnerability of users who may be less suspicious of a phone call than they would be of an email or text message. This tactic increases the chances of success for the fraudsters, as they exploit the trust that people place in direct communication channels.
Google’s response, which includes the development of a feature to block the installation of apps from unknown sources and restrict access to accessibility services, is a step in the right direction. However, it remains to be seen how effective these measures will be in preventing such advanced attacks.
For users, the risk is clear: staying vigilant and cautious is more important than ever. Always check app permissions and reviews before downloading any software. Enabling features like Google Play Protect can add an extra layer of security, but users must also be cautious of social engineering tactics that seek to bypass these protections.
Fact Checker Results
- SuperCard X does indeed employ a multi-layered attack involving social engineering, malicious apps, and NFC relay functionality, as confirmed by Cleafy’s research.
- The malware has been observed to exploit a previously undocumented NFC relay technique for unauthorized card transactions, which is a novel approach to fraud.
- Google is actively working on new features to prevent app installations from unknown sources, which may help mitigate such attacks in the future.
References:
Reported By: thehackernews.com
Extra Source Hub:
https://stackoverflow.com
Wikipedia
Undercode AI
Image Source:
Unsplash
Undercode AI DI v2





