DevilNFC Android Malware Traps Kiosk Mode Devices in NFC Relay Attacks
Key Takeaways A new Android malware, DevilNFC, is actively trapping victims in a fake banking interface using a combination of NFC relay attacks and Android’s Kiosk Mode. The malware targets...
Key Takeaways
- A new Android malware, DevilNFC, is actively trapping victims in a fake banking interface using a combination of NFC relay attacks and Android’s Kiosk Mode.
- The malware targets banking customers primarily in Europe and Latin America, exfiltrating sensitive card data and PINs.
- DevilNFC is a sophisticated, independently developed tool, exhibiting characteristics of AI-assisted development, signaling a new trend in malware creation.
- Victims are lured through phishing messages, leading to the installation of a malicious app disguised as a security update.
- There is no specific patch for DevilNFC itself, but general cybersecurity hygiene and vigilance can prevent infection.
Android Malware DevilNFC Leverages Kiosk Mode for Advanced NFC Relay Attacks
A sophisticated new Android malware, dubbed DevilNFC, has emerged, employing an innovative tactic that combines NFC relay attacks with Android’s Kiosk Mode. This dual-pronged approach ensnares unsuspecting victims within a fraudulent banking interface, effectively locking them into the malicious application until their sensitive card details are successfully stolen.
Table Of Content
Analysts report that DevilNFC is meticulously designed, targeting banking customers across Europe and Latin America with a level of technical precision rarely observed in independently developed tools.
Independent Development and Advanced Capabilities
Unlike many contemporary threats that rely on existing infrastructure or borrowed code, DevilNFC stands out as an entirely custom-built malware. It was developed from the ground up by a distinct threat actor group, highlighting a shift towards more autonomous malware creation. This independent development allows for greater agility and customizability in its attack methodology.
The attack chain typically commences with a phishing message delivered via SMS or WhatsApp. These messages direct targets to a deceptive landing page that meticulously mimics the legitimate Google Play Store. The fraudulent page then presents the malicious application as a critical security update from a recognizable Spanish-language banking institution.
Upon installation, the DevilNFC malware immediately activates, seizing control of the victim’s device. This swift takeover occurs without any immediate indication to the user, who remains unaware of the compromise.
Analysis by Cleafy Reveals Sophistication
The Threat Intelligence and Response team at Cleafy, who first identified and analyzed DevilNFC, noted its advanced nature compared to another recently documented NFC relay family, NFCMultiPay. Although both malware families are actively engaged in NFC relay attacks against banking customers and operate in overlapping geographical regions, Cleafy’s report, shared with Cyber Security News (CSN), confirms they share no common code or infrastructure. The concurrent appearance of these distinct, sophisticated threats marks a significant evolution in the landscape of NFC relay attacks.
A particularly alarming feature of DevilNFC is its ability to completely isolate the victim. Upon launch, the malware leverages Android’s Kiosk Mode to lock down the device. It then displays a social engineering template retrieved from a remote server. This action effectively hides the system UI, disables the hardware back button, and traps the victim within the malicious interface while the NFC relay attack is underway.

Kiosk Mode: A Containment Weapon
Once the victim opens the compromised application, DevilNFC activates Kiosk Mode. This action effectively removes the standard Android user interface and overrides the hardware back button, rendering it unresponsive. The user is thus confined within the malicious application’s interface while the NFC relay session proceeds silently in the background. Following the initial card tap, a fake verification pop-up, dynamically rendered from a Command and Control (C2) server template, prompts the victim to input their four-digit card PIN.

The stolen PIN is then immediately exfiltrated to two distinct locations: a dedicated C2 endpoint and the attacker’s private Telegram channel. This data, including the bank name and the victim’s public IP address, is transmitted in plaintext. To ensure the transaction completes, the malicious interface intentionally triggers a fake verification error, instructing the victim to hold their card against the device for an additional ten seconds. This engineered delay extends the relay window, guaranteeing the transaction’s success before any false “success” screen is displayed.

DevilNFC employs a “Dual-Role APK” architecture, allowing a single application to function as both a passive NFC reader on the victim’s unrooted device and a card emulator on the attacker’s rooted hardware. This is achieved through a hooking framework that injects DevilNFC’s relay module directly into Android’s NFC daemon process. This sophisticated relay pipeline is capable of authorizing various financial transactions, including ATM withdrawals and chip-and-PIN purchases at points of sale globally.
AI-Assisted Development and the Broader Threat Shift
Both DevilNFC and NFCMultiPay exhibit clear indicators of AI-assisted development. In the case of DevilNFC, the phishing templates retrieved from its live C2 server are notably over-engineered for their purpose, featuring CSS and JavaScript with architectural precision and robust, deliberate error handling for edge cases. Similarly, NFCMultiPay’s debug logs display emoji-categorized metric labels bordered by ASCII characters, a pattern highly characteristic of logging scaffolding generated by Large Language Models (LLMs).
These findings suggest that threat actors are increasingly utilizing uncensored AI models in conjunction with leaked malware codebases found in public repositories. This accessibility significantly lowers the barrier to entry for developing functional Android malware, enabling more localized groups to create their own sophisticated tools rather than relying on purchasing access to platforms traditionally offered by larger, often Chinese-speaking, cybercriminal organizations.
This trend is further corroborated by ESET Research, which in April 2025 identified a new NGate variant specifically targeting Brazilian users. This variant also contained injected code showing similar AI development indicators and Portuguese language strings, reinforcing the notion of a global shift towards localized, AI-assisted malware development.
What You Should Do
- Avoid Sideloading Apps: Only install applications from official and trusted sources like the Google Play Store. Exercise extreme caution with links received via SMS, WhatsApp, or email, even if they appear to be from known institutions.
- Verify Security Updates: Legitimate banking institutions will typically not ask you to download security updates via third-party links. Always navigate directly to your bank’s official website or app store page for updates.
- Never Enter PINs Unprompted: Do not enter your card PIN into any interface on your mobile device unless you have explicitly initiated a transaction or authentication process within your bank’s official application.
- Report Suspicious Activity: If your device becomes locked to a full-screen interface or exhibits other suspicious behavior, immediately contact your bank and report the incident to relevant cybersecurity authorities.
- Enable Strong Authentication: Utilize multi-factor authentication (MFA) whenever available for your banking and other sensitive accounts.
- Keep Software Updated: Ensure your Android operating system and all installed applications are kept up-to-date to benefit from the latest security patches.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.