Trojanized Android App Fuels New Wave of NFC Fraud
2026-04-21T20:52:18Z•9fbe5890abfb6ec0ffab2c000e56039ddcc609e5942811cf941794f838ea26a9
AI-securityAPK-malformationAndroidDDoS-takedownDLL-side-loadingFormbookGentlemen-RaaSHandyPayKelpDAOLazarusMiraiNFC-theftNGateNVD-policy-changeOT-waterOpenAI-GPT-5.4-CyberRhysidaSystemBCVercel-breachVulnerability-managementZionSiphonmailbox-rule-abusephishing-fraudransomware
What happened
A broad surge in cybercrime and high-risk vulnerabilities dominated the feed: a trojanized Android app (NGate) abuses the HandyPay payment app to skim NFC card data and PINs in Brazil, while ZionSiphon targets water OT systems for sabotage and ICS scanning. Active exploitation of critical flaws was reported (nginx-ui MCP auth bypass CVE-2026-33032; Mirai campaigns exploiting CVE-2024-3721 in DVRs), and supply-chain/third-party-tool abuse led to a confirmed Vercel incident. Ransomware (Gentlemen RaaS growth, Rhysida breach affecting healthcare), large crypto thefts attributed to Lazarus (KelpDA
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 9fbe5890abfb6ec0ffab2c000e56039ddcc609e5942811cf941794f838ea26a9
- Enrichment time
- 2026-04-21T20:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.