Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft August 2026 Patch Tuesday fixes 394 flaws, including 3 zero-days
August 11, 2026
Critical Zoom Zero-Click Flaws Let Attackers Hijack User Devices
August 11, 2026
DEF CON Attendees Broadcast Fake Wi-Fi Network on Flight
August 11, 2026
Home/Threats/DevilNFC Android Malware Traps Kiosk Mode Devices in NFC Relay Attacks
Threats

DevilNFC Android Malware Traps Kiosk Mode Devices in NFC Relay Attacks

Key Takeaways A new Android malware, DevilNFC, is actively trapping victims in a fake banking interface using a combination of NFC relay attacks and Android’s Kiosk Mode. The malware targets...

Marcus Rodriguez
Marcus Rodriguez
May 20, 2026 5 Min Read
74 0

Key Takeaways

  • A new Android malware, DevilNFC, is actively trapping victims in a fake banking interface using a combination of NFC relay attacks and Android’s Kiosk Mode.
  • The malware targets banking customers primarily in Europe and Latin America, exfiltrating sensitive card data and PINs.
  • DevilNFC is a sophisticated, independently developed tool, exhibiting characteristics of AI-assisted development, signaling a new trend in malware creation.
  • Victims are lured through phishing messages, leading to the installation of a malicious app disguised as a security update.
  • There is no specific patch for DevilNFC itself, but general cybersecurity hygiene and vigilance can prevent infection.

Android Malware DevilNFC Leverages Kiosk Mode for Advanced NFC Relay Attacks

A sophisticated new Android malware, dubbed DevilNFC, has emerged, employing an innovative tactic that combines NFC relay attacks with Android’s Kiosk Mode. This dual-pronged approach ensnares unsuspecting victims within a fraudulent banking interface, effectively locking them into the malicious application until their sensitive card details are successfully stolen.

Table Of Content

  • Key Takeaways
  • Android Malware DevilNFC Leverages Kiosk Mode for Advanced NFC Relay Attacks
  • Independent Development and Advanced Capabilities
  • Analysis by Cleafy Reveals Sophistication
  • Kiosk Mode: A Containment Weapon
  • AI-Assisted Development and the Broader Threat Shift
  • What You Should Do

Analysts report that DevilNFC is meticulously designed, targeting banking customers across Europe and Latin America with a level of technical precision rarely observed in independently developed tools.

Independent Development and Advanced Capabilities

Unlike many contemporary threats that rely on existing infrastructure or borrowed code, DevilNFC stands out as an entirely custom-built malware. It was developed from the ground up by a distinct threat actor group, highlighting a shift towards more autonomous malware creation. This independent development allows for greater agility and customizability in its attack methodology.

The attack chain typically commences with a phishing message delivered via SMS or WhatsApp. These messages direct targets to a deceptive landing page that meticulously mimics the legitimate Google Play Store. The fraudulent page then presents the malicious application as a critical security update from a recognizable Spanish-language banking institution.

Upon installation, the DevilNFC malware immediately activates, seizing control of the victim’s device. This swift takeover occurs without any immediate indication to the user, who remains unaware of the compromise.

Analysis by Cleafy Reveals Sophistication

The Threat Intelligence and Response team at Cleafy, who first identified and analyzed DevilNFC, noted its advanced nature compared to another recently documented NFC relay family, NFCMultiPay. Although both malware families are actively engaged in NFC relay attacks against banking customers and operate in overlapping geographical regions, Cleafy’s report, shared with Cyber Security News (CSN), confirms they share no common code or infrastructure. The concurrent appearance of these distinct, sophisticated threats marks a significant evolution in the landscape of NFC relay attacks.

A particularly alarming feature of DevilNFC is its ability to completely isolate the victim. Upon launch, the malware leverages Android’s Kiosk Mode to lock down the device. It then displays a social engineering template retrieved from a remote server. This action effectively hides the system UI, disables the hardware back button, and traps the victim within the malicious interface while the NFC relay attack is underway.

Notable NFC Relay Malware Families Observed Over the Past Year (Source - Cleafy)
Notable NFC Relay Malware Families Observed Over the Past Year (Source – Cleafy)

Kiosk Mode: A Containment Weapon

Once the victim opens the compromised application, DevilNFC activates Kiosk Mode. This action effectively removes the standard Android user interface and overrides the hardware back button, rendering it unresponsive. The user is thus confined within the malicious application’s interface while the NFC relay session proceeds silently in the background. Following the initial card tap, a fake verification pop-up, dynamically rendered from a Command and Control (C2) server template, prompts the victim to input their four-digit card PIN.

AI artifacts in both malware families (Source - Cleafy)
AI artifacts in both malware families (Source – Cleafy)

The stolen PIN is then immediately exfiltrated to two distinct locations: a dedicated C2 endpoint and the attacker’s private Telegram channel. This data, including the bank name and the victim’s public IP address, is transmitted in plaintext. To ensure the transaction completes, the malicious interface intentionally triggers a fake verification error, instructing the victim to hold their card against the device for an additional ten seconds. This engineered delay extends the relay window, guaranteeing the transaction’s success before any false “success” screen is displayed.

Kiosk Mode for Card Reading and Pin Harvest (Source - Cleafy)
Kiosk Mode for Card Reading and Pin Harvest (Source – Cleafy)

DevilNFC employs a “Dual-Role APK” architecture, allowing a single application to function as both a passive NFC reader on the victim’s unrooted device and a card emulator on the attacker’s rooted hardware. This is achieved through a hooking framework that injects DevilNFC’s relay module directly into Android’s NFC daemon process. This sophisticated relay pipeline is capable of authorizing various financial transactions, including ATM withdrawals and chip-and-PIN purchases at points of sale globally.

AI-Assisted Development and the Broader Threat Shift

Both DevilNFC and NFCMultiPay exhibit clear indicators of AI-assisted development. In the case of DevilNFC, the phishing templates retrieved from its live C2 server are notably over-engineered for their purpose, featuring CSS and JavaScript with architectural precision and robust, deliberate error handling for edge cases. Similarly, NFCMultiPay’s debug logs display emoji-categorized metric labels bordered by ASCII characters, a pattern highly characteristic of logging scaffolding generated by Large Language Models (LLMs).

These findings suggest that threat actors are increasingly utilizing uncensored AI models in conjunction with leaked malware codebases found in public repositories. This accessibility significantly lowers the barrier to entry for developing functional Android malware, enabling more localized groups to create their own sophisticated tools rather than relying on purchasing access to platforms traditionally offered by larger, often Chinese-speaking, cybercriminal organizations.

This trend is further corroborated by ESET Research, which in April 2025 identified a new NGate variant specifically targeting Brazilian users. This variant also contained injected code showing similar AI development indicators and Portuguese language strings, reinforcing the notion of a global shift towards localized, AI-assisted malware development.

What You Should Do

  • Avoid Sideloading Apps: Only install applications from official and trusted sources like the Google Play Store. Exercise extreme caution with links received via SMS, WhatsApp, or email, even if they appear to be from known institutions.
  • Verify Security Updates: Legitimate banking institutions will typically not ask you to download security updates via third-party links. Always navigate directly to your bank’s official website or app store page for updates.
  • Never Enter PINs Unprompted: Do not enter your card PIN into any interface on your mobile device unless you have explicitly initiated a transaction or authentication process within your bank’s official application.
  • Report Suspicious Activity: If your device becomes locked to a full-screen interface or exhibits other suspicious behavior, immediately contact your bank and report the incident to relevant cybersecurity authorities.
  • Enable Strong Authentication: Utilize multi-factor authentication (MFA) whenever available for your banking and other sensitive accounts.
  • Keep Software Updated: Ensure your Android operating system and all installed applications are kept up-to-date to benefit from the latest security patches.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical PinTheft Linux flaw lets attackers gain root access

Next Post

Trapdoor Android Ad Fraud Operation Uses 455 Malicious Apps

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
LLM API Vulnerability Exposes AI Model Reasoning, Poses Data Risk
August 11, 2026
Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption
August 11, 2026
Critical Ivanti Endpoint Manager CVEs Let Remote Attackers Crash Agent Service
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us