Listen to this Post

A New Era of Mobile Banking Fraud Emerges
Brazil’s banking sector is facing a dangerous new cyber threat: PhantomCard, an Android-based NFC-driven Trojan capable of relaying victims’ card data in real time to criminals for fraudulent transactions. Developed from Chinese NFC relay Malware-as-a-Service (MaaS) technology, this malware is being customized and resold by a well-known Brazilian cybercriminal, operating under the alias “Go1ano Developer.”
Initially disguised as a legitimate “Card Protection” app and distributed through fake Google Play pages, PhantomCard tricks victims into tapping their physical bank cards on their infected smartphones. Once the card’s NFC data and PIN are captured, criminals can execute real-time transactions on ATMs or POS terminals thousands of miles away — with the payment systems believing the legitimate cardholder is present.
The campaign, uncovered by mobile security firm ThreatFabric, highlights a disturbing trend: highly sophisticated NFC-based attacks are now being made accessible to low-skill fraudsters through the MaaS economy. And while PhantomCard is currently focused on Brazilian targets, all signs point toward an impending global expansion.
the Original
Origin & Development: PhantomCard is based on Chinese-developed NFC relay malware known as NFU Pay, resold and customized for Brazilian cybercriminal operations. Its infrastructure contains Chinese debug messages, with a /baxi/b C2 endpoint referencing “Brazil” in Chinese.
Distribution Method: Spread via fake Google Play Store pages posing as “Proteção Cartões” apps, complete with fake positive reviews to build credibility.
Attack Mechanism:
1. Victim installs the malicious app.
- The app requests the victim to tap their EMV card on their phone.
- NFC data is captured using the scuba_smartcards library and ISO-DEP protocols.
4. Victim’s PIN is also requested.
- Data is instantly relayed to a fraudster’s POS/ATM, enabling live, remote payments.
Fraud in Action: Telegram videos show a victim tapping their card while a fraudster makes payments in another location, in real time.
MaaS Model: Go1ano Developer is not the original creator, but a reseller of the malware, offering ready-to-use builds to less skilled criminals.
Risk to Banks: Transactions appear legitimate since they’re authenticated with the real card and PIN. Only unusual merchant/location metadata might hint at fraud.
Global Threat Potential: Although initially tailored for Brazil, NFU Pay developers can produce region-specific variants, suggesting PhantomCard could soon target other countries.
Similar Campaigns: Another NFC-relay MaaS, SuperCard X, has been used in Italy for similar attacks, also originating from Chinese-speaking developer circles.
Trend Insight: NFC-based fraud is growing due to increasing contactless card usage and weaknesses in current fraud detection systems.
What Undercode Say:
PhantomCard is not just another banking trojan — it represents the commercialization of highly advanced, hardware-level financial fraud tools. Ten years ago, executing such an NFC relay attack required deep technical expertise, expensive equipment, and physical proximity to the victim. Now, thanks to the MaaS ecosystem, the barrier to entry has dropped dramatically.
The danger here is threefold:
- Accessibility to Low-Skill Criminals — A cybercriminal with minimal coding knowledge can now rent or purchase PhantomCard from a reseller like Go1ano Developer and launch an NFC relay campaign in days.
-
Real-Time Relay Fraud — Unlike cloned card fraud, which may trigger alerts, PhantomCard transactions mimic legitimate in-person purchases because the physical card and PIN are used in the transaction process — albeit remotely. This makes them almost invisible to traditional fraud detection.
-
International Scalability — The
/baxi/bendpoint suggests the current build is Brazil-focused. But the modular code and MaaS business model make it trivial to create UK, EU, or US-targeted builds with local language, currency, and merchant data optimizations.
From a financial institution’s perspective, this is a nightmare. The fraud bypasses most rules-based systems. Geo-location mismatches may trigger some alerts, but criminals can easily blend transactions into normal patterns by targeting merchants in plausible regions.
From a consumer’s perspective, the threat is even worse: You don’t even need to lose your card physically for criminals to drain your account — a single tap on a compromised phone could be enough. The victim may only realize the theft after funds are gone, and recovery can be difficult.
The MaaS trend in financial cybercrime mirrors developments in ransomware: modularity, localization, and affiliate models mean rapid adaptation to different markets. In this case, PhantomCard could evolve into a multi-continent fraud wave by the end of 2026.
Brazil was likely chosen as the testing ground because of high mobile banking adoption, heavy use of contactless payments, and weaker NFC transaction monitoring compared to Europe or the US. But once perfected, the operation can scale globally, targeting regions with similarly high NFC usage.
On a technical level, PhantomCard leverages ISO 14443-4 communication — a standard in most EMV cards — meaning the same approach could work in almost any country where NFC transactions are standard.
The fact that a similar Chinese-developed NFC-relay malware, SuperCard X, has already been deployed in Italy is a red flag: this is not a Brazil-only problem. The developers are clearly selling multiple product lines to different resellers, each targeting specific geographies.
If banks fail to upgrade NFC fraud detection systems, the next wave of cybercrime will happen not via phishing or malware on PCs, but via invisible live relay attacks at the hardware level. This is harder to detect, harder to stop, and — in MaaS form — much harder to trace.
🔍 Fact Checker Results
✅ PhantomCard is indeed a real malware variant identified by ThreatFabric in July 2025 targeting Brazilian users.
✅ Evidence confirms its origin from Chinese NFC relay MaaS code (NFU Pay) and its customization by “Go1ano Developer.”
❌ No proof yet of active global deployment, but the infrastructure suggests expansion potential.
📊 Prediction
By mid-2026, NFC-relay malware like PhantomCard will likely spread beyond Brazil, with localized builds targeting at least five additional countries. Banks will respond by investing heavily in real-time behavioral analytics for NFC transactions, and regulators may push for stricter two-factor authentication in contactless payments. However, without widespread consumer awareness, adoption of such security measures will lag — giving attackers a 12–18 month window of high profitability before the fraud model becomes less viable.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: securityaffairs.com
Extra Source Hub:
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




