Find notable cyber news and cases, enriched with sources, timelines, and signals.

NFCShare fake banking-app update phishing campaign

Campaign
First reported
Last updated
Happening score
H score 40
1 unique sources, 1 articles

Summary

Hide ▲

The NFCShare phishing campaign is using fake banking-app updates on GitHub to steal payment card data from customers of multiple banks across Europe, expanding the theft risk across a broad financial-services target set. The operation combines impersonated bank login pages, deceptive update prompts, and malicious Android packages to capture card details and a 4-digit PIN. It matters because the theft path is built for reusable fraud against bank customers rather than a single isolated lure.

Related Happenings

Ousaban banking trojan retooled for Spain and Portugal

Malware Activity
H score33 First: 01.07.2026 16:45 Last: 01.07.2026 16:45 Sources 1

About this happening: The Ousaban banking trojan has been retooled to target banking customers in Spain and Portugal, raising the risk of credential theft and bank fraud. It uses ...

Rust-based clipboard hijacker that swaps wallet addresses

Malware Activity
H score10 First: 17.06.2026 21:14 Last: 17.06.2026 21:14 Sources 1

About this happening: The Rust-based clipper is a Windows and macOS malware activity that replaces copied cryptocurrency wallet addresses with attacker-controlled destinations. It continuou...

Ghost Networks crypto-clipper promotion campaign

Campaign
H score15 First: 17.06.2026 21:14 Last: 17.06.2026 21:14 Sources 1

About this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...

GitBait phishing campaign targeting Mexican banks

Campaign
H score20 First: 17.06.2026 17:00 Last: 17.06.2026 17:00 Sources 1

About this happening: A long-running GitBait phishing campaign is stealing banking credentials from customers of Mexican financial institutions, using GitHub Pages and SheetBest to...

Rokarolla Android banking trojan activity

Malware Activity
H score26 First: 16.06.2026 16:15 Last: 16.06.2026 16:15 Sources 1

About this happening: The Rokarolla Android banking trojan is expanding phone-level control on infected devices, letting attackers steal credentials, intercept authentication codes, and hide fr...

Timeline

  1. 09.06.2026 01:11 1 articles · 1mo ago

    GitHub repository starts hosting NFCShare banking-app APKs

    Campaign Scope Update

    A GitHub repository used for NFCShare distribution is created on April 10 and goes on to host 56 unique APKs that impersonate mobile banking apps, primarily for banks in Italy and Spain, widening the malware distribution infrastructure.

    Show sources
  2. 09.06.2026 01:11 1 articles · 1mo ago

    Phishing sites push bank customers to NFCShare malicious APKs

    Exploitation Observed

    Beginning May 14, victims across Europe visit phishing sites that impersonate real banks, are prompted to update a banking app, and are redirected to a GitHub repository hosting a malicious APK; after a fake verification screen asks them to place a card near the device NFC chip, NFCShare reads the card using Android’s IsoDep interface and EMV commands.

    Show sources
  3. 09.06.2026 01:11 2 articles · 1mo ago

    Researchers report NFCShare variants targeting bank customers across Europe

    Technical Analysis Update

    D3Lab, which first documented NFCShare in January 2026, reports new variants of the Android malware being distributed as fake updates for legitimate banking apps hosted on GitHub, targeting customers of multiple banks and financial institutions across Europe; the newer samples add malformed APK packaging to hinder automated analysis, while the malware steals the card number, type, expiry date, and a 4-digit PIN before exfiltrating them to a C2 host over WebSocket.

    Show sources